A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does not have proper authorization checks for the file_transfer feature in ssmctl-client command. This could allow an authenticated, lowly privileged local attacker to read or write to any file on server or sensor.
References
| Link | Resource |
|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-882673.html | Vendor Advisory |
Configurations
History
10 Dec 2025, 21:38
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://cert-portal.siemens.com/productcert/html/ssa-882673.html - Vendor Advisory | |
| First Time |
Siemens sinec Security Monitor
Siemens |
|
| CPE | cpe:2.3:a:siemens:sinec_security_monitor:*:*:*:*:*:*:*:* |
09 Dec 2025, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-09 16:17
Updated : 2025-12-10 21:38
NVD link : CVE-2025-40830
Mitre link : CVE-2025-40830
CVE.ORG link : CVE-2025-40830
JSON object : View
Products Affected
siemens
- sinec_security_monitor
CWE
CWE-285
Improper Authorization
