6.5
CVSSv2

CVE-2022-24282

Published: 08/03/2022 Updated: 10/10/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). The affected system allows to upload JSON objects that are deserialized to Java objects. Due to insecure deserialization of user-supplied content by the affected software, a privileged attacker could exploit this vulnerability by sending a maliciously crafted serialized Java object. This could allow the malicious user to execute arbitrary code on the device with root privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

siemens sinec network management system

ICS Advisories

Siemens SINEC NMS
Critical Infrastructure Sectors: Energy