CVE-2021-33732
Status: ModifiedHigh (7.2)—
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Base score: 7.2
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 28%
- Percentile among all scored CVEs: 98
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-89
References
Raw JSON (NVD)
Show
{
"id": "CVE-2021-33732",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.2,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "productcert@siemens.com",
"affectedData": [
{
"vendor": "Siemens",
"product": "SINEC NMS",
"versions": [
{
"status": "affected",
"version": "All versions < V1.0 SP2 Update 1"
}
]
}
]
}
],
"published": "2021-10-12T10:15:12.207",
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-163251.pdf",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "productcert@siemens.com"
},
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-163251.pdf",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "productcert@siemens.com",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application."
},
{
"lang": "es",
"value": "Se ha identificado una vulnerabilidad en SINEC NMS (Todas las versiones anteriores a V1.0 SP2 Update 1). Un atacante autenticado con privilegios podría ejecutar comandos arbitrarios en la base de datos local mediante el envío de peticiones diseñadas al servidor web de la aplicación afectada"
}
],
"lastModified": "2026-06-17T03:55:07.510",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:siemens:sinec_nms:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2B59D696-F272-40DA-8DC6-423D9E5026C0",
"versionEndExcluding": "1.0"
},
{
"criteria": "cpe:2.3:a:siemens:sinec_nms:1.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4ED13FC8-63C0-42C6-A51C-C480C45327C2"
},
{
"criteria": "cpe:2.3:a:siemens:sinec_nms:1.0:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E68FE047-8F53-46B8-82D4-9342B1C8CA55"
},
{
"criteria": "cpe:2.3:a:siemens:sinec_nms:1.0:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5F2C66EC-5A29-4B92-AEDB-7DB8A5CA7391"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "productcert@siemens.com"
}