CVE-2020-25237: Siemens SINEC NMS FirmwareFileUtils extractToFolder Directory Traversal Remote Code Execution Vulnerability

Published Feb 9, 2021
·
Updated

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1 Update 1), SINEMA Server (All versions < V14.0 SP2 Update 2). When uploading files to an affected system using a zip container, the system does not correctly check if the relative file path of the extracted files is still within the intended target directory. With this an attacker could create or overwrite arbitrary files on an affected system. This type of vulnerability is also known as 'Zip-Slip'. (ZDI-CAN-12054)

Other sources

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens SINEC NMS. Authentication is required to exploit this vulnerability. The specific flaw exists within the FirmwareFileUtils class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.

ZDI

Affected Software

11 affected componentsFixes available
Siemens SINEC NMS
Siemens Sinec Network Management System<1.0
Siemens Sinec Network Management System=1.0
Siemens Sinec Network Management System=1.0-sp1
Siemens SINEMA Server<14.0
Siemens SINEMA Server=14.0
Siemens SINEMA Server=14.0-sp1
Siemens SINEMA Server=14.0-sp2
Siemens SINEMA Server=14.0-sp2_update1
Siemens SINEC NMS SP1 Update 1<1.0
1.0
Siemens SINEMA Server SP2 Update 2<14.0
14.0

Event History

Feb 9, 2021
CVE Published
via MITRE·03:38 PM
Data Sourced
via MITRE·03:38 PM
DescriptionWeakness
Feb 24, 2025
Advisory Published
via ZDI·02:46 AM

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2020-25237?

CVE-2020-25237 is a vulnerability in Siemens SINEC NMS and SINEMA Server that allows remote code execution through a directory traversal vulnerability when uploading files using a zip container.

2

Which software versions are affected by CVE-2020-25237?

The affected software versions are SINEC NMS < V1.0 SP1 Update 1 and SINEMA Server < V14.0 SP2 Update 2.

3

What is the severity of CVE-2020-25237?

The severity of CVE-2020-25237 is rated as high with a CVSS score of 8.8.

4

How does CVE-2020-25237 work?

CVE-2020-25237 works by exploiting a directory traversal vulnerability in the file extraction process when uploading files using a zip container. This allows an attacker to execute arbitrary code remotely.

5

How can I mitigate the CVE-2020-25237 vulnerability?

To mitigate the CVE-2020-25237 vulnerability, it is recommended to update Siemens SINEC NMS to version 1.0 SP1 Update 1 or later, and SINEMA Server to version 14.0 SP2 Update 2 or later. Additionally, users should follow best security practices such as restricting access to the affected systems and monitoring for any suspicious activity.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203