Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-43rq-xvwq-hp7q

Опубликовано: 10 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 7.8

Описание

A vulnerability has been identified in SINEC NMS (All versions), User Management Component (UMC) (All versions < V2.15.2.1). The affected application permits improper modification of a configuration file by a low-privileged user. This could allow an attacker to load malicious DLLs, potentially leading to arbitrary code execution with SYSTEM privileges.(ZDI-CAN-28108)

A vulnerability has been identified in SINEC NMS (All versions), User Management Component (UMC) (All versions < V2.15.2.1). The affected application permits improper modification of a configuration file by a low-privileged user. This could allow an attacker to load malicious DLLs, potentially leading to arbitrary code execution with SYSTEM privileges.(ZDI-CAN-28108)

EPSS

Процентиль: 15%
0.00238
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 7.8
nvd
6 месяцев назад

A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3), User Management Component (UMC) (All versions < V2.15.2.1). The affected application permits improper modification of a configuration file by a low-privileged user. This could allow an attacker to load malicious DLLs, potentially leading to arbitrary code execution with SYSTEM privileges.(ZDI-CAN-28108)

CVSS3: 7.8
fstec
6 месяцев назад

Уязвимость компонента User Management Component (UMC) системы управления сетями передачи данных SINEC NMS, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 15%
0.00238
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-427