CVE-2025-40755

8.8

Siemens · SINEC NMS

Siemens SINEC NMS contains an SQL injection vulnerability in the getTotalAndFilterCounts endpoint, allowing authenticated low-privileged attackers to escalate privileges.

Executive summary

A critical SQL injection vulnerability in Siemens SINEC NMS allows authenticated low-privileged attackers to gain elevated privileges through the getTotalAndFilterCounts endpoint.

Vulnerability

This is an SQL injection flaw (CWE-89) located in the getTotalAndFilterCounts endpoint. An authenticated, low-privileged attacker can inject malicious SQL commands to modify database contents and achieve privilege escalation.

Business impact

The ability for an authenticated user to perform SQL injection and escalate privileges poses a significant risk to the integrity and confidentiality of the network management system. Given the CVSS score of 8.8, this vulnerability is classified as High severity. Successful exploitation could lead to unauthorized administrative control over the management platform, potentially facilitating further lateral movement or disruption of industrial network monitoring.

Remediation

Immediate Action: Upgrade Siemens SINEC NMS to version V4.0 SP1 or later as specified in the official Siemens security advisory.

Proactive Monitoring: Review system access logs for unusual patterns or suspicious database queries originating from low-privileged user accounts.

Compensating Controls: Implement strict network segmentation to limit access to the management interface and deploy a Web Application Firewall to filter malicious SQL syntax from incoming requests.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents a significant security risk for environments utilizing Siemens SINEC NMS. Organizations should prioritize updating their software to version V4.0 SP1 immediately to eliminate the underlying SQL injection flaw and prevent potential privilege escalation by malicious insiders or compromised user accounts.

More Siemens CVEs

Sources