CVE-2026-25656: High severity Siemens SINEC NMS vulnerability
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3), User Management Component (UMC) (All versions < V2.15.2.1). The affected application permits improper modification of a configuration file by a low-privileged user. This could allow an attacker to load malicious DLLs, potentially leading to arbitrary code execution with SYSTEM privileges.(ZDI-CAN-28108)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25656?
CVE-2026-25656 is considered a high-severity vulnerability due to its potential exploitation by low-privileged users.
How do I fix CVE-2026-25656?
To fix CVE-2026-25656, upgrade the SINEC NMS User Management Component to version 2.15.2.1 or later.
What components are affected by CVE-2026-25656?
CVE-2026-25656 affects all versions of SINEC NMS and its User Management Component prior to V2.15.2.1.
What are the potential risks associated with CVE-2026-25656?
The risks of CVE-2026-25656 include unauthorized modification of configuration files, leading to the potential loading of malicious DLLs.
Who is impacted by CVE-2026-25656?
Any user of affected versions of SINEC NMS, particularly those with low privileges who can modify configuration settings, is impacted by CVE-2026-25656.