CVE-2026-25655Disclosure(siemens / sinec_nms)

LOWCVSS 8.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch siemens sinec_nms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP2). The affected application permits improper modification of a configuration file by a low-privileged user. This could allow an attacker to load malicious DLLs, potentially leading to arbitrary code execution with administrative privilege.(ZDI-CAN-28107)

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-427

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sinec_nms

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-10); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
sinec_nms

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-02-10: 2Mentions · 2026-02-13: 2Patch / Workaround · 2026-02-13: 1Technical Details · 2026-02-10: 2Technical Details · 2026-02-13: 102-1002-13
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-102
Disclosure2
2026-02-132
Disclosure1Patch1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25655 DLL Hijacking in Siemens SINEC NMS Versions Below V4.0 SP2 (ICS) https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25655

    Post summary

    A DLL hijacking vulnerability in Siemens SINEC NMS versions below 4.0 SP2 has been disclosed, with no PoC, exploit, or patch details provided in the text.

    0001055
    4.0K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Siemens ❗ CVE-2026-25656 ❗ CVE-2026-25655 ❗ CVE-2025-40936 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-siemens-3/ https://t.co/Y8ZxJcLVfr

    Post summary

    A brief announcement of three Siemens product CVEs with a link to additional information, lacking technical details or exploitation context.

    00000102
    6.6K followersView on X
  • Kernyx64@kernyx64
    Patch

    12/02/2026 🚨 Multiple Siemens SINEC NMS versions are vulnerable to local privilege escalation (CVE-2026-25655, CVE-2026-25656), allowing low-privileged attackers to execute arbitrary code with elevated privileges. Update to SINEC NMS V4.0 SP2 or later, and UMC to V2.15.2.1 or later immediately. https://www.cisa.gov/news-events/ics-advisories/icsa-26-043-01

    Post summary

    The advisory announces local privilege escalation vulnerabilities in Siemens SINEC NMS and provides specific patch versions, emphasizing the need for immediate update.

    0000054
    25 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25655 A vulnerability has been identified in SINEC NMS (All versions &lt; V4.0 SP2). The affected application permits improper modification of a configuration file by a low-pr… https://www.cve.org/CVERecord?id=CVE-2026-25655

    Post summary

    CVE‑2026‑25655 is a disclosure of a configuration‑file modification vulnerability in SINEC NMS, affecting all versions below V4.0 SP2.

    00000200
    56.5K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appsiemenssinec_nms---
Appsiemenssinec_nms4.0--
Appsiemenssinec_nms4.0--

Explore more