Количество 3
Количество 3

CVE-2025-40737
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded ZIP files. This could allow an attacker to write arbitrary files to restricted locations and potentially execute code with elevated privileges (ZDI-CAN-26571).
GHSA-fg27-6v6q-r3w4
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded ZIP files. This could allow an attacker to write arbitrary files to restricted locations and potentially execute code with elevated privileges (ZDI-CAN-26571).

BDU:2025-08984
Уязвимость метода unZipJarFilestoLocation системы сетевого управления для мониторинга промышленными сетями Siemens SINEC NMS, позволяющая нарушителю получить несанкционированный доступ на запись файлов и выполнить произвольный код
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2025-40737 A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded ZIP files. This could allow an attacker to write arbitrary files to restricted locations and potentially execute code with elevated privileges (ZDI-CAN-26571). | CVSS3: 8.8 | 0% Низкий | около 1 месяца назад |
GHSA-fg27-6v6q-r3w4 A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded ZIP files. This could allow an attacker to write arbitrary files to restricted locations and potentially execute code with elevated privileges (ZDI-CAN-26571). | CVSS3: 8.8 | 0% Низкий | около 1 месяца назад | |
![]() | BDU:2025-08984 Уязвимость метода unZipJarFilestoLocation системы сетевого управления для мониторинга промышленными сетями Siemens SINEC NMS, позволяющая нарушителю получить несанкционированный доступ на запись файлов и выполнить произвольный код | CVSS3: 8.8 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу