CVE-2026-25654: High severity Siemens SINEC NMS vulnerability
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate user authorization when processing password reset requests. This could allow an authenticated remote attacker to bypass authorization checks, leading to the ability to reset the password of any arbitrary user account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25654?
CVE-2026-25654 is considered a high severity vulnerability due to unauthorized access risks.
How do I fix CVE-2026-25654?
To fix CVE-2026-25654, upgrade to SINEC NMS version 4.0 SP3 or later.
What type of attack is possible with CVE-2026-25654?
CVE-2026-25654 allows an authenticated remote attacker to bypass authorization checks during password reset requests.
Which versions of SINEC NMS are affected by CVE-2026-25654?
All versions of SINEC NMS prior to version 4.0 SP3 are affected by CVE-2026-25654.
What can an attacker achieve by exploiting CVE-2026-25654?
By exploiting CVE-2026-25654, an attacker could potentially reset passwords and gain unauthorized access to the system.