Metrics
Affected Vendors & Products
Tue, 14 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized Password Reset in Siemens SINEC NMS |
Tue, 14 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens sinec-nms |
|
| Vendors & Products |
Siemens
Siemens sinec-nms |
Tue, 14 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate user authorization when processing password reset requests. This could allow an authenticated remote attacker to bypass authorization checks, leading to the ability to reset the password of any arbitrary user account. | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2026-04-14T13:46:23.821Z
Reserved: 2026-02-04T06:26:41.260Z
Link: CVE-2026-25654
Updated: 2026-04-14T13:46:21.224Z
Status : Received
Published: 2026-04-14T09:16:35.150
Modified: 2026-04-14T09:16:35.150
Link: CVE-2026-25654
No data.
OpenCVE Enrichment
Updated: 2026-04-14T16:30:39Z