Vulnerability Details CVE-2023-44315
A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application improperly sanitizes certain SNMP configuration data retrieved from monitored devices. An attacker with access to a monitored device could prepare a stored cross-site scripting (XSS) attack that may lead to unintentional modification of application data by legitimate users.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 63.4%
CVSS Severity
CVSS v3 Score 4.7
Products affected by CVE-2023-44315
-
cpe:2.3:a:siemens:sinec_nms:1.0
-
cpe:2.3:a:siemens:sinec_nms:1.0.3