CVE-2021-33728

CWE-502: DESERIALIZATION OF UNTRUSTED DATA
The affected system allows uploading JSON objects that are deserialized to Java objects. Due to insecure deserialization of user-supplied content by the affected software, a privileged attacker could exploit this vulnerability by sending a crafted serialized Java object.
The latest update for SINEC NMS fixes multiple vulnerabilities. The most severe could allow an authenticated remote attacker to execute arbitrary code on the system, with system privileges, under certain conditions. Siemens has released an update for SINEC NMS and recommends to update to the latest version.

Risk Information

  • CVE ID
  • CVE-2021-33728
  • Vendor
  • Siemens
  • Product
  • SINEC NMS
  • CVSS v3
  • 7.2