← back
CVE-2026-24032

CVE-2026-24032

CVSS 6.9 MEDIUMEPSS 0.3%CWE-347
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected application contains an authentication weakness due to insufficient validation of user identity in the UMC component. This could allow an unauthenticated remote attacker to bypass authentication and gain unauthorized access to the application. (ZDI-CAN-27564)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Affected products
Siemens · SINEC NMS

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →