ZDI-CAN-28107: ZDI-26-131: Siemens SINEC NMS Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Siemens SINEC NMS. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-25655.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28107?
The severity of ZDI-CAN-28107 is high due to its potential to allow local privilege escalation.
How do I fix ZDI-CAN-28107?
To fix ZDI-CAN-28107, ensure that all software configurations adhere to the updated security guidelines provided by Siemens.
Who is affected by ZDI-CAN-28107?
ZDI-CAN-28107 affects users of Siemens SINEC NMS who are running vulnerable installations.
What type of attack does ZDI-CAN-28107 facilitate?
ZDI-CAN-28107 facilitates local privilege escalation attacks, allowing attackers to gain higher-level access.
Do I need to update my software for ZDI-CAN-28107?
Yes, it is recommended to update your Siemens SINEC NMS software to mitigate the risks associated with ZDI-CAN-28107.