Siemens SINEC NMS SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in Siemens SINEC NMS, affecting all versions prior to 4.0. This vulnerability allows an unauthenticated remote attacker to execute arbitrary SQL queries on the server database.

Impact

Exploitation of this vulnerability could lead to unauthorized access to the database, allowing attackers to execute arbitrary SQL commands, potentially leading to data manipulation or extraction.

Remediation

Users are advised to update to SINEC NMS version 4.0 or later. For guidance on updating, please refer to the Siemens Industry Support page.

Added: Jul 8, 2025, 11:40 AM
Updated: Jul 8, 2025, 11:40 AM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
2.5
exploitability
7.0
remediation
7.9
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.