Improper Privilege Management in SINEC NMS - CVE-2022-25311

 

Improper Privilege Management in SINEC NMS - CVE-2022-25311

Published: March 10, 2022


Vulnerability identifier: #VU61226
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25311
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to the affected software do not properly check privileges between users during the same web browser session, creating an unintended sphere of control. A local user can escalate privileges.


Affected software

SINEC NMS

How to mitigate CVE-2022-25311

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins