Siemens SINEC NMS
cpe:2.3:a:siemens:sinec_network_management_system:*:*:*:*:*:*:*, +2 more
- < V4.0 SP2
A local privilege escalation vulnerability has been identified in Siemens SINEC NMS, affecting all versions prior to V4.0 SP2. This vulnerability allows a low-privileged user to improperly modify a configuration file, which could enable the loading of malicious DLLs. Such an action could lead to arbitrary code execution with administrative privileges.
Exploitation of this vulnerability could result in unauthorized modification of configuration files, allowing for the execution of malicious DLLs and potentially leading to arbitrary code execution with elevated privileges.
Siemens has released a patch for this vulnerability. Users are advised to update to SINEC NMS V4.0 SP2 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.