Siemens
Siemens Sinec NMS: vulnerabilidades y CVE
Siemens Sinec NMS tiene 48 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 9 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE48
Últimos 12 meses5
Críticas9
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
| CVE-2021-40438 | Crítica (9) | 100% | ⚠ Explotación activa | 16 sept 2021 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-25654 | Alta (8.7) | 0.53% | — | 14 abr 2026 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate user authorization when processing password reset requests. This could allow an authenticated remote… |
| CVE-2026-24032 | Media (6.9) | 0.25% | — | 14 abr 2026 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected application contains an authentication weakness due to insufficient validation of user identity in the UMC component.… |
| CVE-2026-25656 | Alta (8.5) | 0.19% | — | 10 feb 2026 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3), User Management Component (UMC) (All versions < V2.15.2.1). The affected application permits improper modification of a configuration file by a… |
| CVE-2026-25655 | Alta (8.5) | 0.19% | — | 10 feb 2026 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP2). The affected application permits improper modification of a configuration file by a low-privileged user. This could allow an attacker to load… |
| CVE-2025-40755 | Alta (8.7) | 0.37% | — | 14 oct 2025 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP1). Affected applications are vulnerable to SQL injection through getTotalAndFilterCounts endpoint. An authenticated low privileged attacker could… |
| CVE-2025-40738 | Alta (8.7) | 10% | — | 8 jul 2025 | A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded ZIP files. This could allow an attacker to write arbitrary… |
| CVE-2025-40737 | Alta (8.7) | 10% | — | 8 jul 2025 | A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded ZIP files. This could allow an attacker to write arbitrary… |
| CVE-2025-40736 | Crítica (9.3) | 0.44% | — | 8 jul 2025 | A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application exposes an endpoint that allows an unauthorized modification of administrative credentials. This could allow an… |
| CVE-2025-40735 | Alta (8.7) | 0.51% | — | 8 jul 2025 | A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected devices are vulnerable to SQL injection. This could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the… |
| CVE-2025-30176 | Alta (8.7) | 0.62% | — | 13 may 2025 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation… |
| CVE-2025-30175 | Alta (8.7) | 0.62% | — | 13 may 2025 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation… |
| CVE-2025-30174 | Alta (8.7) | 0.62% | — | 13 may 2025 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation… |
| CVE-2024-49775 | Crítica (9.3) | 1.5% | — | 16 dic 2024 | A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2501.0001), Opcenter Intelligence (All versions < V2501.0001), Opcenter Quality (All versions < V2512), Opcenter RDnL (All versions <… |
| CVE-2024-47808 | Alta (8.3) | 0.14% | — | 12 nov 2024 | A vulnerability has been identified in SINEC NMS (All versions < V3.0 SP1). The affected application contains a database function, that does not properly restrict the permissions of users to write to the filesystem of… |
| CVE-2024-33698 | Crítica (9.3) | 1.1% | — | 10 sept 2024 | A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS… |
| CVE-2024-41941 | Media (5.3) | 0.26% | — | 13 ago 2024 | A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This could allow an authenticated attacker to bypass the checks and modify… |
| CVE-2024-41940 | Crítica (9.4) | 0.56% | — | 13 ago 2024 | A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly validate user input to a privileged command queue. This could allow an authenticated attacker to execute… |
| CVE-2024-41939 | Alta (8.7) | 0.51% | — | 13 ago 2024 | A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This could allow an authenticated attacker to bypass the checks and… |
| CVE-2024-41938 | Media (5.1) | 0.26% | — | 13 ago 2024 | A vulnerability has been identified in SINEC NMS (All versions < V3.0). The importCertificate function of the SINEC NMS Control web application contains a path traversal vulnerability. This could allow an authenticated… |
| CVE-2024-36398 | Alta (8.5) | 0.17% | — | 13 ago 2024 | A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application executes a subset of its services as `NT AUTHORITY\SYSTEM`. This could allow a local attacker to execute operating system… |
| CVE-2023-46280 | Alta (8.2) | 0.26% | — | 14 may 2024 | A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 Upd5), SIMATIC NET PC Software V16… |
| CVE-2024-31978 | Alta (7.6) | 0.46% | — | 9 abr 2024 | A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP2). Affected devices allow authenticated users to export monitoring data. The corresponding API endpoint is susceptible to path traversal and could… |
| CVE-2024-23812 | Alta (8.8) | 1.1% | — | 13 feb 2024 | A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application incorrectly neutralizes special elements when creating a report which could lead to command injection. |
| CVE-2024-23811 | Alta (8.8) | 0.39% | — | 13 feb 2024 | A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application allows users to upload arbitrary files via TFTP. This could allow an attacker to upload malicious firmware images or… |
| CVE-2024-23810 | Crítica (9.8) | 0.65% | — | 13 feb 2024 | A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application is vulnerable to SQL injection. This could allow an unauthenticated remote attacker to execute arbitrary SQL queries… |
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
| CVE-2023-44315 | Media (5.4) | 0.30% | — | 10 oct 2023 | A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application improperly sanitizes certain SNMP configuration data retrieved from monitored devices. An attacker with access to a… |
| CVE-2022-30527 | Alta (7.8) | 0.16% | — | 10 oct 2023 | A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application assigns improper access rights to specific folders containing executable files and libraries. This could allow an… |
| CVE-2021-42550 | Media (6.6) | 4.4% | — | 16 dic 2021 | In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers. |
| CVE-2021-33736 | Alta (7.2) | 1.2% | — | 12 oct 2021 | A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.