Siemens / Sinec Nms
57 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-25654 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate user authorization when processing passw… | HIGH | 8.7 | Apr 14, 2026 |
| CVE-2026-24032 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected application contains an authentication weakness due to insuff… | MEDIUM | 6.9 | Apr 14, 2026 |
| CVE-2026-25656 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3), User Management Component (UMC) (All versions < V2.15.2.1). The affected applicatio… | HIGH | 8.5 | Feb 10, 2026 |
| CVE-2026-25655 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP2). The affected application permits improper modification of a configuration file by a… | HIGH | 8.5 | Feb 10, 2026 |
| CVE-2025-40755 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP1). Affected applications are vulnerable to SQL injection through getTotalAndFilterCoun… | HIGH | 8.7 | Oct 14, 2025 |
| CVE-2025-30033 | The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an applicat… | HIGH | 8.5 | Aug 12, 2025 |
| CVE-2025-40738 | A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded… | HIGH | 8.7 | Jul 8, 2025 |
| CVE-2025-40737 | A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded… | HIGH | 8.7 | Jul 8, 2025 |
| CVE-2025-40736 | A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application exposes an endpoint that allows an unauthorized modification o… | CRITICAL | 9.3 | Jul 8, 2025 |
| CVE-2025-40735 | A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected devices are vulnerable to SQL injection. This could allow an unauthenticat… | HIGH | 8.7 | Jul 8, 2025 |
| CVE-2025-30176 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote… | HIGH | 8.7 | May 13, 2025 |
| CVE-2025-30175 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote… | HIGH | 8.7 | May 13, 2025 |
| CVE-2025-30174 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote… | HIGH | 8.7 | May 13, 2025 |
| CVE-2024-49775 | A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2501.0001), Opcenter Intelligence (All versions < V2501.0001), Opcenter Q… | CRITICAL | 9.3 | Dec 16, 2024 |
| CVE-2024-47808 | A vulnerability has been identified in SINEC NMS (All versions < V3.0 SP1). The affected application contains a database function, that does not properly restr… | HIGH | 8.3 | Nov 12, 2024 |
| CVE-2024-33698 | A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMA… | CRITICAL | 9.3 | Sep 10, 2024 |
| CVE-2024-41941 | A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This could all… | MEDIUM | 5.3 | Aug 13, 2024 |
| CVE-2024-41940 | A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly validate user input to a privileged command… | CRITICAL | 9.4 | Aug 13, 2024 |
| CVE-2024-41939 | A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This could all… | HIGH | 8.7 | Aug 13, 2024 |
| CVE-2024-41938 | A vulnerability has been identified in SINEC NMS (All versions < V3.0). The importCertificate function of the SINEC NMS Control web application contains a path… | MEDIUM | 5.1 | Aug 13, 2024 |
| CVE-2024-36398 | A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application executes a subset of its services as `NT AUTHORITY\SYSTEM`. Th… | HIGH | 8.5 | Aug 13, 2024 |
| CVE-2023-46280 | A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1… | HIGH | 8.2 | May 14, 2024 |
| CVE-2024-31978 | A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP2). Affected devices allow authenticated users to export monitoring data. The correspon… | HIGH | 7.6 | Apr 9, 2024 |
| CVE-2024-23812 | A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application incorrectly neutralizes special elements when creating a r… | HIGH | 8.8 | Feb 13, 2024 |
| CVE-2024-23811 | A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application allows users to upload arbitrary files via TFTP. This coul… | HIGH | 8.8 | Feb 13, 2024 |
Showing 1 to 25 of 57 CVEs