PT-2026-32608 · Siemens · Sinec Nms

Published

2026-04-14

·

Updated

2026-04-30

·

CVE-2026-25654

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SINEC NMS versions prior to V4.0 SP3
Description An issue exists where user authorization is not properly validated during the processing of password reset requests. This allows an authenticated remote attacker to bypass authorization checks and reset the password of any arbitrary user account.
Recommendations Update to V4.0 SP3.

Fix

LPE

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-25654
ZDI-26-297

Affected Products

Sinec Nms