CVE Tools

Sinec Nms

63 CVEs tracked. 2 of them are in CISA KEV.

This hub aggregates every CVE we track for Sinec Nms, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.

Sinec Nms CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Sinec Nms CVEs per month
MonthCVEs
2024-100
2024-111
2024-121
2025-010
2025-020
2025-030
2025-040
2025-053
2025-060
2025-074
2025-081
2025-090
2025-101
2025-110
2025-120
2026-010
2026-022
2026-030
2026-042
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 63 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical813%
  • High4571%
  • Medium1016%

Latest CVEs

The 15 most recently published vulnerabilities affecting Sinec Nms.

  1. CVE-2026-25654A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate user authorization when processing password reset requests. This could allow a...8.8
  2. CVE-2026-24032A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected application contains an authentication weakness due to insufficient validation of user identity in ...7.3
  3. CVE-2026-25656A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3), User Management Component (UMC) (All versions < V2.15.2.1). The affected application permits improper modification of a c...7.8
  4. CVE-2026-25655A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP2). The affected application permits improper modification of a configuration file by a low-privileged user. This could allo...7.8
  5. CVE-2025-40755A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP1). Affected applications are vulnerable to SQL injection through getTotalAndFilterCounts endpoint. An authenticated low priv...8.8
  6. CVE-2025-30033The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup compo...7.8
  7. CVE-2025-40738A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded ZIP files. This could allow an attack...8.8
  8. CVE-2025-40737A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded ZIP files. This could allow an attack...8.8
  9. CVE-2025-40736A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application exposes an endpoint that allows an unauthorized modification of administrative credentials. This cou...9.8
  10. CVE-2025-40735A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected devices are vulnerable to SQL injection. This could allow an unauthenticated remote attacker to execute arbitrar...8.8
  11. CVE-2025-30176A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integ...7.5
  12. CVE-2025-30175A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integ...7.5
  13. CVE-2025-30174A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integ...7.5
  14. CVE-2024-49775A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2501.0001), Opcenter Intelligence (All versions < V2501.0001), Opcenter Quality (All versions < V2512), Opcente...9.8
  15. CVE-2024-47808A vulnerability has been identified in SINEC NMS (All versions < V3.0 SP1). The affected application contains a database function, that does not properly restrict the permissions of users to write ...8.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store