ZDI-26-297: Siemens SINEC NMS Improper Authentication Privilege Escalation Vulnerability
Published Apr 23, 2026
·Updated
This vulnerability allows remote attackers to escalate privileges on affected installations of Siemens SINEC NMS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-25654.
Affected Software
1 affected component
Siemens SINEC NMS
Event History
Apr 23, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-26-297?
The severity of ZDI-26-297 is rated at 8.8, indicating a high risk of privilege escalation.
2
How do I fix ZDI-26-297?
To mitigate ZDI-26-297, ensure that the latest security patches and updates from Siemens for SINEC NMS are applied.
3
What type of vulnerability is ZDI-26-297?
ZDI-26-297 is classified as an improper authentication privilege escalation vulnerability.
4
Who is affected by ZDI-26-297?
Users of Siemens SINEC NMS installations are affected by ZDI-26-297.
5
Is authentication required to exploit ZDI-26-297?
Yes, authentication is required to exploit the ZDI-26-297 vulnerability.