CVE-2025-40830

MEDIUM

SINEC Security Monitor < 4.10.0 - Authenticated Arbitrary File Read and Write via ssmctl-client File Transfer

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does not have proper authorization checks for the file_transfer feature in ssmctl-client command. This could allow an authenticated, lowly privileged local attacker to read or write to any file on server or sensor.

References (1)

Core 1

Scores

CVSS v3 6.7
EPSS 0.0014
EPSS Percentile 3.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-285
Status published
Products (1)
siemens/sinec_security_monitor < 4.10.0
Published Dec 09, 2025
Tracked Since Feb 18, 2026