Authorization Weakness in SINEC Security Monitor by Siemens
CVE-2025-40830
8.4HIGH
What is CVE-2025-40830?
A vulnerability was identified in SINEC Security Monitor that is present in all versions prior to V4.10.0. This issue arises due to insufficient authorization checks within the file_transfer feature of the ssmctl-client command. As a result, an authenticated, but low-privileged local attacker may exploit this weakness to manipulate or access files on the server or sensor without appropriate permissions.
Affected Version(s)
SINEC Security Monitor 0