PT-2025-28396 · Sinec Nms · Sinec Nms
CVE-2025-40738
·
Publicado
2025-07-08
·
Atualizado
2025-07-09
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
SINEC NMS versions prior to V4.0
Description:
A security issue has been identified in the affected application, where it does not properly validate file paths when extracting uploaded ZIP files. This could allow an attacker to write arbitrary files to restricted locations and potentially execute code with elevated privileges.
Recommendations:
For versions prior to V4.0, update to version V4.0 or later to resolve the issue. As a temporary workaround, consider restricting the upload of ZIP files or implementing additional validation on file paths to minimize the risk of exploitation.
Correção
RCE
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sinec Nms