VDB

CVE-2025-40737

CVE-2025-40737 PUBLISHED CVSS 8.800000190734863 HIGH

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded ZIP files. This could allow an attacker to write arbitrary files to restricted locations and potentially execute code with elevated privileges (ZDI-CAN-26571).

EPSS 1.72% · 82.8th percentile

Risk Scores

CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
1.72%
82.8th percentile

Affected Products

VendorProductVersions
SiemensSINEC NMS0
siemenssinec_nms0

Timeline

  • Jul 8, 2025 EPSS Score
  • Jul 8, 2025 Coalition ESS Score
  • Jul 8, 2025 PoC Published
  • Jul 8, 2025 CVE Published
  • Jul 8, 2025 PoC Published
  • Jul 9, 2025 Coalition ESS Score
  • Jul 10, 2025 PoC Published
  • Jul 18, 2025 EPSS Score
  • Jul 27, 2025 EPSS Score
  • Aug 6, 2025 EPSS Score
  • Aug 15, 2025 EPSS Score
  • Aug 21, 2025 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›