Medium severity6.5NVD Advisory· Published Oct 12, 2021· Updated Jun 17, 2026
CVE-2021-33723
CVE-2021-33723
Description
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could change the user profile of any user without proper authorization. With this, the attacker could change the password of any user in the affected system.
Affected products
6cpe:2.3:a:siemens:sinec_nms:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:siemens:sinec_nms:*:*:*:*:*:*:*:*range: <1.0
- cpe:2.3:a:siemens:sinec_nms:1.0:-:*:*:*:*:*:*
- cpe:2.3:a:siemens:sinec_nms:1.0:sp1:*:*:*:*:*:*
- cpe:2.3:a:siemens:sinec_nms:1.0:sp2:*:*:*:*:*:*
- (no CPE)range: < V1.0 SP2 Update 1
- (no CPE)range: All versions < V1.0 SP2 Update 1
Patches
Vulnerability mechanics
References
1- cert-portal.siemens.com/productcert/pdf/ssa-163251.pdfnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.