CVE-2026-25656
7.8Siemens · SINEC NMS and User Management Component (UMC)
Siemens SINEC NMS and UMC are vulnerable to improper modification of configuration files, which could allow a low-privileged user to achieve arbitrary code execution with SYSTEM privileges.
Executive summary
A vulnerability in Siemens SINEC NMS and User Management Component allows low-privileged users to achieve arbitrary code execution with SYSTEM privileges via improper configuration file modification.
Vulnerability
This flaw is an uncontrolled search path element (CWE-427) where the application permits low-privileged, authenticated users to modify configuration files, facilitating the loading of malicious DLLs.
Business impact
The ability for a low-privileged user to execute arbitrary code with SYSTEM privileges represents a critical security failure, effectively granting an attacker full control over the affected host. Given the CVSS score of 7.8, this vulnerability poses a significant risk to the integrity and availability of network management systems, potentially leading to unauthorized lateral movement or complete system compromise.
Remediation
Immediate Action: Update Siemens SINEC NMS to version V4.0 SP3 or later and User Management Component to V2.15.2.1 or later as specified in the vendor security advisory.
Proactive Monitoring: Monitor system logs for unauthorized access to configuration directories or the unexpected creation of new DLL files within the application path.
Compensating Controls: Restrict local user permissions on the host system to prevent unauthorized modification of application configuration files by non-administrator users.
Exploitation status
Public Exploit Available: No — exploit_available (unknown).
Analyst recommendation
This vulnerability presents a severe risk by allowing privilege escalation to the highest level of system authority. Organizations running affected Siemens software should prioritize the application of the vendor-provided security patches immediately to mitigate the risk of unauthorized code execution.