The vendor explicitly identifies these products as affected by this CVE.
- SINEC NMS
- Summary
- A vulnerability in Node.js allows for bypassing restrictions set by the --experimental-permission flag using the built-in inspector module (node:inspector). By exploiting the Worker class's ability to create an "internal worker" with the kIsInternal Symbol, attackers can modify the isInternal value when an inspector is attached within the Worker constructor before initializing a new WorkerImpl.
- Remediation
- Update to V2.0 SP1 or later version
