The vendor explicitly identifies these products as affected by this CVE.
- SINEC NMS
- Summary
- fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the --allow-fs-read flag in Node.js. This vulnerability arises from a missing check in the fs.openAsBlob() API.
- Remediation
- Update to V2.0 SP1 or later version
