A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP1). Affected applications are vulnerable to SQL injection through getTotalAndFilterCounts endpoint. An authenticated low privileged attacker could exploit to insert data and achieve privilege escalation. (ZDI-CAN-26570)
Metrics
Affected Vendors & Products
References
History
Tue, 21 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens sinec Nms
|
|
| CPEs | cpe:2.3:a:siemens:sinec_nms:*:*:*:*:*:*:*:* cpe:2.3:a:siemens:sinec_nms:4.0:-:*:*:*:*:*:* |
|
| Vendors & Products |
Siemens sinec Nms
|
Mon, 20 Oct 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens sinec-nms |
|
| Vendors & Products |
Siemens
Siemens sinec-nms |
Tue, 14 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Oct 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP1). Affected applications are vulnerable to SQL injection through getTotalAndFilterCounts endpoint. An authenticated low privileged attacker could exploit to insert data and achieve privilege escalation. (ZDI-CAN-26570) | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published: 2025-10-14T09:15:13.820Z
Updated: 2025-10-14T18:58:59.719Z
Reserved: 2025-04-16T08:39:30.031Z
Link: CVE-2025-40755
Updated: 2025-10-14T18:58:55.887Z
Status : Analyzed
Published: 2025-10-14T10:15:37.817
Modified: 2025-10-21T14:40:48.760
Link: CVE-2025-40755
No data.