CVE-2025-40830: High severity SINEC SINEC Security Monitor vulnerability
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does not have proper authorization checks for the filetransfer feature in ssmctl-client command. This could allow an authenticated, lowly privileged local attacker to read or write to any file on server or sensor.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SINEC Security Monitorto a version that resolves this vulnerability.Fixed in V4.10.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40830?
CVE-2025-40830 is considered a moderate severity vulnerability due to improper authorization checks.
How do I fix CVE-2025-40830?
To fix CVE-2025-40830, upgrade to SINEC Security Monitor version 4.10.0 or later.
Who is affected by CVE-2025-40830?
CVE-2025-40830 affects all versions of SINEC Security Monitor prior to version 4.10.0.
What type of attacks can CVE-2025-40830 enable?
CVE-2025-40830 can enable authenticated local attackers to read or write unauthorized files using the file_transfer feature.
What products are impacted by CVE-2025-40830?
CVE-2025-40830 impacts the SINEC Security Monitor application.