Impact
The vulnerability allows a low‑privileged user to modify a configuration file in Siemens SINEC NMS and the User Management Component. This can lead to loading malicious DLLs and executing arbitrary code with SYSTEM privileges. The weakness is identified as CWE‑427, an uncontrolled search path element.
Affected Systems
Siemens SINEC NMS versions earlier than V4.0 SP3; Siemens User Management Component versions earlier than V2.15.2.1.
Risk and Exploitability
The CVSS v3 score is 8.5, indicating high severity. The EPSS score is below 1 %, showing a very low exploitation probability at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; a user with limited privileges needs only write access to the configuration file to trigger the exploit and can elevate privileges to SYSTEM through malicious DLL loading.
OpenCVE Enrichment