漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3), User Management Component (UMC) (All versions < V2.15.2.1). The affected application permits improper modification of a configuration file by a low-privileged user. This could allow an attacker to load malicious DLLs, potentially leading to arbitrary code execution with SYSTEM privileges.(ZDI-CAN-28108)
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
对搜索路径元素未加控制
Vulnerability Title
Siemens SINEC NMS和Siemens User Management Component 代码问题漏洞
Vulnerability Description
Siemens SINEC NMS和Siemens User Management Component都是德国西门子(Siemens)公司的产品。Siemens SINEC NMS是 一个网络管理系统 (NMS),该系统可用于全天候集中监控、管理和配置具有数万台设备的工业网络,包括与安全相关的领域。Siemens User Management Component是一个集中式身份管理平台。 Siemens SINEC NMS和Siemens User Management Component V2.15.
CVSS Information
N/A
Vulnerability Type
N/A