ZDI-26-297: Siemens SINEC NMS Improper Authentication Privilege Escalation Vulnerability

Inhalt

This vulnerability allows remote attackers to escalate privileges on affected installations of Siemens SINEC NMS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-25654.

Verknuepfte CVEs

CVE-ID Severity (CVE.org) CVSS (CVE.org) EPSS EPSS-% Veroeffentlicht (CVE.org)

CVE-2026-25654

HIGH 8.8 - - 2026-04-14

Quellen-Details

Bezeichnung Name Kategorie Tags Zielgruppe Sprache Feed-URL
Zero Day Initiative (Published)

zdi_pub

threat_intel - de https://www.zerodayinitiative.com/rss/published/