PT-2026-7259 · Siemens · Sinec Nms+1

Published

2026-02-10

·

Updated

2026-02-25

·

CVE-2026-25656

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SINEC NMS versions prior to 2.15.2.1 User Management Component (UMC) versions prior to 2.15.2.1
Description The application allows unauthorized modification of a configuration file by a user with limited privileges. This could enable an attacker to load malicious DLLs, potentially resulting in arbitrary code execution with SYSTEM privileges.
Recommendations Update SINEC NMS to version 2.15.2.1 or later. Update User Management Component (UMC) to version 2.15.2.1 or later.

Fix

LPE

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2026-05799
CVE-2026-25656
ZDI-26-132

Affected Products

Sinec Nms
User Management