CVE-2026-25656
published 2026-02-10CVE-2026-25656: A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3), User Management Component (UMC) (All versions < V2.15.2.1). The affected…
PriorityP345high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
14.9th percentile
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3), User Management Component (UMC) (All versions < V2.15.2.1). The affected application permits improper modification of a configuration file by a low-privileged user.
This could allow an attacker to load malicious DLLs, potentially leading to arbitrary code execution with SYSTEM privileges.(ZDI-CAN-28108)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | sinec_nms | < V4.0 SP3 | V4.0 SP3 |
| siemens | user_management_component | < V2.15.2.1 | V2.15.2.1 |
| siemens | user_management_component | < 2.15.2.1 | 2.15.2.1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.5HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-43rq-xvwq-hp7q: A vulnerability has been identified in SINEC NMS (All versions), User Management Component (UMC) (All versions < V2
ghsa_unreviewed·2026-02-10
CVE-2026-25656 [HIGH] CWE-427 GHSA-43rq-xvwq-hp7q: A vulnerability has been identified in SINEC NMS (All versions), User Management Component (UMC) (All versions < V2
A vulnerability has been identified in SINEC NMS (All versions), User Management Component (UMC) (All versions < V2.15.2.1). The affected application permits improper modification of a configuration file by a low-privileged user.
This could allow an attacker to load malicious DLLs, potentially leading to arbitrary code execution with SYSTEM privileges.(ZDI-CAN-28108)
CISA ICS
Siemens SINEC NMS
cisa_ics·2026-02-12·CVSS 7.8
[HIGH] Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateFebruary 12, 2026
Alert CodeICSA-26-043-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Multiple Siemens products are affected by two local privilege escalation vulnerabilities which could allow an low privileged attacker to load malicious DLLs, potentially leading to arbitrary code execution with elevated privileges. Siemens has released new versions for the affected products and recommends to update to the latest versions.
The following versions of Siemens SINEC NMS are affected:
- SINEC NMS: Versions prior to V4.0 SP2 (CVE-2026-25655)
- SINEC NMS: All Versions (CVE-2026-25656)
- User Management Component (UMC) vers:intdot/<2.15.2.1 (CVE-2026-2565
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-02-10
Published