cert-portal.siemens.com
https://cert-portal.siemens.com/productcert/html/ssa-605717.html CVE-2026-25654
HIGH
SINEC NMS Authorization Bypass via Password Reset
Record summary
CVE-2026-25654 has a selected CVSS score of 8.7 (high).
Description
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate user authorization when processing password reset requests. This could allow an authenticated remote attacker to bypass authorization checks, leading to the ability to reset the password of any arbitrary user account.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 14, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SINEC NMSBrowse Siemens / SINEC NMSDefault status: unknown | CVE List | Before V4.0 SP3 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-25654