A vulnerability has been identified in SINEMA Server V14 (All versions). The affected application improperly sanitizes certain SNMP configuration data retrieved from monitored devices. An attacker with access to a monitored device could perform a stored cross-site scripting (XSS) attack that may lead to arbitrary code execution with `SYSTEM` privileges on the application server. (ZDI-CAN-19823)
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: siemens

Published: 2023-10-10T10:21:20.721Z

Updated: 2023-10-10T10:21:20.721Z

Reserved: 2023-06-17T10:50:05.752Z


Link: CVE-2023-35796

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-10-10T11:15:11.733

Modified: 2023-10-24T12:25:01.420


Link: CVE-2023-35796

JSON object: View

cve-icon Redhat Information

No data.

CWE