Siemens SINEC Security Monitor Confidential Information Disclosure Vulnerability

Vulnerability

A vulnerability exists in Siemens SINEC Security Monitor in all versions prior to 4.9.0, allowing the application to unintentionally expose confidential information through metadata and files. This information includes details about contributors and email addresses, which can be accessed on the SSM Server.

Impact

Exploitation of this vulnerability leads to unauthorized disclosure of sensitive information, including contributor details and email addresses, via metadata and files on the SSM Server.

Remediation

Users are advised to update SINEC Security Monitor to version 4.9.0 or later. For more information, visit the Siemens Industry Support page.

Added: Mar 10, 2026, 7:04 PM
Updated: Mar 10, 2026, 7:04 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.2
remediation
0.0
relevance
3.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.