Siemens SINEC NMS
cpe:2.3:a:siemens:sinec_network_management_system:*:*:*:*:*:*:*, +2 more
- < V4.0 SP3
An authentication bypass vulnerability has been identified in Siemens SINEC NMS, all versions prior to 4.0 SP3 when used with the User Management Component (UMC). This vulnerability arises from inadequate validation of user identity in the UMC component, potentially allowing an unauthenticated remote attacker to bypass authentication and gain unauthorized access to the application.
Exploitation of this vulnerability could lead to unauthorized access to the application by bypassing authentication mechanisms.
Users are advised to update to SINEC NMS version 4.0 SP3 or later. Additional information can be found on the Siemens support website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.