This content is restricted.
Brief
Here is a summary of the provided document:
Summary:
Siemens has identified two vulnerabilities in its SINEC NMS equipment, with a CVSS v4 score of 7.2. The vulnerabilities, CVE-2023-5678 and CVE-2024-31978, are related to improper check for unusual or exceptional conditions and improper limitation of a pathname to a restricted directory. An attacker could exploit these vulnerabilities to impact the confidentiality, integrity, and availability of the affected devices.
The affected devices are all versions of SINEC NMS prior to V2.0 SP2. Siemens has recommended patching the devices to the latest version to mitigate the risks. Additionally, CISA recommends minimizing network exposure, locating devices behind firewalls, and using secure remote access methods.
No publicly known exploit has been reported to CISA at this time.
Highlights content goes here...
This content is restricted.