CVE-2026-25655: High severity Siemens SINEC NMS vulnerability
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP2). The affected application permits improper modification of a configuration file by a low-privileged user. This could allow an attacker to load malicious DLLs, potentially leading to arbitrary code execution with administrative privilege.(ZDI-CAN-28107)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25655?
CVE-2026-25655 is considered a high severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2026-25655?
To remediate CVE-2026-25655, upgrade SINEC NMS to version 4.0 SP2 or later.
What type of vulnerability is CVE-2026-25655?
CVE-2026-25655 is an improper modification vulnerability that allows low-privileged users to alter a configuration file.
Who is affected by CVE-2026-25655?
Any users of SINEC NMS versions prior to 4.0 SP2 are affected by CVE-2026-25655.
What can an attacker do with CVE-2026-25655?
An attacker exploiting CVE-2026-25655 could load malicious DLLs, potentially leading to arbitrary code execution with administrative privileges.