Skip to main content

Vendor/product archive

siemens / sinec_nms CVEs

Beta · best-effort

40 CVEs tagged to siemens / sinec_nms5 Critical, 28 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2026-25655

Published Feb 10, 2026

A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP2). The affected application permits improper modification of a configuration file by a low-privileged user…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-40755

Published Oct 14, 2025

A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP1). Affected applications are vulnerable to SQL injection through getTotalAndFilterCounts endpoint. An auth…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-40738

Published Jul 8, 2025

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded ZIP files. This cou…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-40737

Published Jul 8, 2025

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded ZIP files. This cou…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-40736

Published Jul 8, 2025

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application exposes an endpoint that allows an unauthorized modification of administrative cre…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-40735

Published Jul 8, 2025

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected devices are vulnerable to SQL injection. This could allow an unauthenticated remote attacker t…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-47808

Published Nov 12, 2024

A vulnerability has been identified in SINEC NMS (All versions < V3.0 SP1). The affected application contains a database function, that does not properly restrict the permissions…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-41941

Published Aug 13, 2024

A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This could allow an authenticated…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41940

Published Aug 13, 2024

A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly validate user input to a privileged command queue. This could al…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-41939

Published Aug 13, 2024

A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This could allow an authenticated…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-41938

Published Aug 13, 2024

A vulnerability has been identified in SINEC NMS (All versions < V3.0). The importCertificate function of the SINEC NMS Control web application contains a path traversal vulnerabi…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36398

Published Aug 13, 2024

A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application executes a subset of its services as `NT AUTHORITY\SYSTEM`. This could allow a loc…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23812

Published Feb 13, 2024

A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application incorrectly neutralizes special elements when creating a report which could le…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23811

Published Feb 13, 2024

A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application allows users to upload arbitrary files via TFTP. This could allow an attacker…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23810

Published Feb 13, 2024

A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application is vulnerable to SQL injection. This could allow an unauthenticated remote att…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-44315

Published Oct 10, 2023

A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application improperly sanitizes certain SNMP configuration data retrieved from monitored devi…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30527

Published Oct 10, 2023

A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application assigns improper access rights to specific folders containing executable files and…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-33736

Published Oct 12, 2021

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-33735

Published Oct 12, 2021

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 40 CVEsPage 1 of 2