cbcvebase.

Siemens Sinec Nms vulnerabilities

61 known vulnerabilities affecting siemens/sinec_nms.

Total CVEs
61
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL8HIGH41MEDIUM11LOW1

Vulnerabilities

Page 2 of 4
CVE-2024-23812P3HIGHCVSS 8.8fixed in 2.0v2.0+1 more2024-02-13
CVE-2024-23812 [HIGH] CWE-78 CVE-2024-23812: A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application incorrectly neutralizes special elements when creating a report which could lead to command injection.
nvd
CVE-2024-41939P3HIGHCVSS 8.8fixed in 3.0fixed in V3.02024-08-13
CVE-2024-41939 [HIGH] CWE-863 CVE-2024-41939: A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application doe A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This could allow an authenticated attacker to bypass the checks and elevate their privileges on the application.
nvd
CVE-2025-40755P3HIGHCVSS 8.8fixed in 4.0v4.0+1 more2025-10-14
CVE-2025-40755 [HIGH] CWE-89 CVE-2025-40755: A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP1). Affected applications ar A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP1). Affected applications are vulnerable to SQL injection through getTotalAndFilterCounts endpoint. An authenticated low privileged attacker could exploit to insert data and achieve privilege escalation. (ZDI-CAN-26570)
nvd
CVE-2026-24032P3HIGHCVSS 7.3fixed in V4.0 SP32026-04-14
CVE-2026-24032 [HIGH] CWE-347 CVE-2026-24032: A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected ap A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected application contains an authentication weakness due to insufficient validation of user identity in the UMC component. This could allow an unauthenticated remote attacker to bypass authentication and gain unauthorized access to the application. (ZDI-CAN-27
nvd
CVE-2022-25311P3HIGHCVSS 8.8vAll versions >= V1.0.3 < V2.0vAll versions < V1.0.32022-03-08
CVE-2022-25311 [HIGH] CWE-269 CVE-2022-25311: A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All ver A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). The affected software do not properly check privileges between users during the same web browser session, creating an unintended sphere of control. This could allow an authenticated low privileged user
nvd
CVE-2021-33725P3CRITICALCVSS 9.1fixed in 1.0v1.0+1 more2021-10-12
CVE-2021-33725 [CRITICAL] CWE-22 CVE-2021-33725: A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected sy A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to delete arbitrary files or directories under a user controlled path and does not correctly check if the relative path is still within the intended target directory.
nvd
CVE-2024-23811P3HIGHCVSS 8.8fixed in 2.0v2.0+1 more2024-02-13
CVE-2024-23811 [HIGH] CWE-434 CVE-2024-23811: A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application allows users to upload arbitrary files via TFTP. This could allow an attacker to upload malicious firmware images or other files, that could potentially lead to remote code execution.
nvd
CVE-2021-33724P3CRITICALCVSS 9.1fixed in 1.0v1.0+1 more2021-10-12
CVE-2021-33724 [CRITICAL] CWE-22 CVE-2021-33724: A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected sy A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system contains an Arbitrary File Deletion vulnerability that possibly allows to delete an arbitrary file or directory under a user controlled path.
nvd
CVE-2022-24281P3HIGHCVSS 7.2vAll versions < V1.0.32022-03-08
CVE-2022-24281 [HIGH] CWE-89 CVE-2022-24281: A vulnerability has been identified in SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All ver A vulnerability has been identified in SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). A privileged authenticated attacker could execute arbitrary commands in the local database by sending specially crafted requests to the webserver of the affected application.
nvd
CVE-2021-33721P3HIGHCVSS 7.2vAll versions < V1.0 SP22021-08-10
CVE-2021-33721 [HIGH] CWE-78 CVE-2021-33721: A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2). The affected application A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2). The affected application incorrectly neutralizes special elements when creating batch operations which could lead to command injection. An authenticated remote attacker with administrative privileges could exploit this vulnerability to execute arbitrary code on the system with
nvd
CVE-2023-46281P3HIGHCVSS 8.8fixed in V2.0 SP12023-12-12
CVE-2023-46281 [HIGH] CWE-942 CVE-2023-46281: A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcente A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), T
nvd
CVE-2021-33728P3HIGHCVSS 7.2fixed in 1.0v1.0+1 more2021-10-12
CVE-2021-33728 [HIGH] CWE-502 CVE-2021-33728: A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected sy A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to upload JSON objects that are deserialized to JAVA objects. Due to insecure deserialization of user-supplied content by the affected software, a privileged attacker could exploit this vulnerability by sending a crafted serialized Java obje
nvd
CVE-2024-31978P3HIGHCVSS 7.6fixed in V2.0 SP22024-04-09
CVE-2024-31978 [HIGH] CWE-22 CVE-2024-31978: A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP2). Affected devices allow a A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP2). Affected devices allow authenticated users to export monitoring data. The corresponding API endpoint is susceptible to path traversal and could allow an authenticated attacker to download files from the file system. Under certain circumstances the downloaded files are deleted f
nvd
CVE-2026-25655P3HIGHCVSS 7.8fixed in 4.0v4.0+1 more2026-02-10
CVE-2026-25655 [HIGH] CWE-427 CVE-2026-25655: A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP2). The affected application A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP2). The affected application permits improper modification of a configuration file by a low-privileged user. This could allow an attacker to load malicious DLLs, potentially leading to arbitrary code execution with administrative privilege.(ZDI-CAN-28107)
nvd
CVE-2022-24282P3HIGHCVSS 7.2vAll versions >= V1.0.3 < V2.0vAll versions < V1.0.32022-03-08
CVE-2022-24282 [HIGH] CWE-502 CVE-2022-24282: A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All ver A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). The affected system allows to upload JSON objects that are deserialized to Java objects. Due to insecure deserialization of user-supplied content by the affected software, a privileged attacker could ex
nvd
CVE-2026-25656P3HIGHCVSS 7.8fixed in V4.0 SP32026-02-10
CVE-2026-25656 [HIGH] CWE-427 CVE-2026-25656: A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3), User Management Componen A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3), User Management Component (UMC) (All versions < V2.15.2.1). The affected application permits improper modification of a configuration file by a low-privileged user. This could allow an attacker to load malicious DLLs, potentially leading to arbitrary code execution with SYSTEM
nvd
CVE-2019-6575P3HIGHCVSS 7.5vAll versions < V1.0 SP12019-04-17
CVE-2019-6575 [HIGH] CWE-248 CVE-2019-6575: A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions = V2.5 < V2.6.1), SIMATIC S7-1500 Software Controller (All versions between V2.5 (including) and V2.7 (excluding)), SIMATIC WinCC OA (All versions < V3.15 P018), SIMATIC WinCC Runtime Advanc
nvd
CVE-2025-30175P3HIGHCVSS 7.5fixed in 4.0fixed in V4.02025-05-13
CVE-2025-30175 [HIGH] CWE-787 CVE-2025-30175: A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (Al A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation
nvd
CVE-2025-30176P3HIGHCVSS 7.5fixed in 4.0fixed in V4.02025-05-13
CVE-2025-30176 [HIGH] CWE-125 CVE-2025-30176: A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (Al A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation
nvd
CVE-2025-30174P3HIGHCVSS 7.5fixed in 4.0fixed in V4.02025-05-13
CVE-2025-30174 [HIGH] CWE-125 CVE-2025-30174: A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (Al A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation
nvd
Siemens Sinec Nms vulnerabilities | cvebase