A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does not have proper authorization checks for the file_transfer feature in ssmctl-client command. This could allow an authenticated, lowly privileged local attacker to read or write to any file on server or sensor.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:siemens:sinec_security_monitor:*:*:*:*:*:*:*:* |
Wed, 10 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens sinec Security Monitor |
|
| Vendors & Products |
Siemens
Siemens sinec Security Monitor |
Tue, 09 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does not have proper authorization checks for the file_transfer feature in ssmctl-client command. This could allow an authenticated, lowly privileged local attacker to read or write to any file on server or sensor. | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published: 2025-12-09T10:44:32.353Z
Updated: 2025-12-09T15:45:31.431Z
Reserved: 2025-04-16T08:50:26.976Z
Link: CVE-2025-40830
Updated: 2025-12-09T15:45:27.917Z
Status : Analyzed
Published: 2025-12-09T16:17:46.677
Modified: 2025-12-10T21:38:56.833
Link: CVE-2025-40830
No data.