PT-2026-7258 · Siemens · Sinec Nms

Published

2026-02-10

·

Updated

2026-02-25

·

CVE-2026-25655

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SINEC NMS versions prior to 4.0 SP2
Description The application allows unauthorized modification of a configuration file by a user with limited privileges. This could enable an attacker to load malicious DLLs, potentially resulting in arbitrary code execution with administrative privileges.
Recommendations Update to version 4.0 SP2 or later.

Fix

LPE

RCE

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-01855
CVE-2026-25655
ZDI-26-131

Affected Products

Sinec Nms