Siemens SINEC Network Management System Logback Component
SINEC NMS versions before 1.0.3 contain a vulnerability in the logback component (CVE-2021-42550) that allows attackers with write access to the logback.xml configuration file to execute arbitrary code on the management system. The vulnerability stems from insecure deserialization in the logback component. Exploitation requires the attacker to already have write access to the configuration file, which is a high-complexity prerequisite. No known public exploits target this vulnerability. Siemens has released version 1.0.3 with a fix.
- Write access to logback.xml configuration file
- Local or local-network access to the SINEC NMS system
- Engineering or administrative credentials
- High privilege level on the system
Patching may require device reboot — plan for process interruption
/api/v1/advisories/731bcaef-e522-4291-ab88-66c77aae0cedGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.