CVE-2023-44315: Siemens Sinec Nms

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application improperly sanitizes certain SNMP configuration data retrieved from monitored devices. An attacker with access to a monitored device could prepare a stored cross-site scripting (XSS) attack that may lead to unintentional modification of application data by legitimate users.

Affected products

  • Siemens Sinec Nms: before 2.0 (fixed in 2.0)

Published 2023-10-10. Last modified 2026-06-17.