Siemens SINEC NMS
cpe:2.3:a:siemens:sinec_network_management_system:*:*:*:*:*:*:*, +2 more
- < V2.15.2.1
A local privilege escalation vulnerability has been identified in Siemens SINEC NMS and the User Management Component (UMC) versions prior to 2.15.2.1. This vulnerability allows a low-privileged user to improperly modify a configuration file, potentially leading to the execution of malicious DLLs and arbitrary code with SYSTEM privileges.
Exploitation of this vulnerability could result in unauthorized modification of configuration files, allowing for the execution of malicious DLLs and arbitrary code with elevated SYSTEM privileges.
Users of the User Management Component (UMC) should update to version 2.15.2.1 or later. For more information, visit the Siemens support page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.