CVE-2020-25237: Siemens SINEC NMS FirmwareFileUtils extractToFolder Directory Traversal Remote Code Execution Vulnerability
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1 Update 1), SINEMA Server (All versions < V14.0 SP2 Update 2). When uploading files to an affected system using a zip container, the system does not correctly check if the relative file path of the extracted files is still within the intended target directory. With this an attacker could create or overwrite arbitrary files on an affected system. This type of vulnerability is also known as 'Zip-Slip'. (ZDI-CAN-12054)
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens SINEC NMS. Authentication is required to exploit this vulnerability. The specific flaw exists within the FirmwareFileUtils class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-25237?
CVE-2020-25237 is a vulnerability in Siemens SINEC NMS and SINEMA Server that allows remote code execution through a directory traversal vulnerability when uploading files using a zip container.
Which software versions are affected by CVE-2020-25237?
The affected software versions are SINEC NMS < V1.0 SP1 Update 1 and SINEMA Server < V14.0 SP2 Update 2.
What is the severity of CVE-2020-25237?
The severity of CVE-2020-25237 is rated as high with a CVSS score of 8.8.
How does CVE-2020-25237 work?
CVE-2020-25237 works by exploiting a directory traversal vulnerability in the file extraction process when uploading files using a zip container. This allows an attacker to execute arbitrary code remotely.
How can I mitigate the CVE-2020-25237 vulnerability?
To mitigate the CVE-2020-25237 vulnerability, it is recommended to update Siemens SINEC NMS to version 1.0 SP1 Update 1 or later, and SINEMA Server to version 14.0 SP2 Update 2 or later. Additionally, users should follow best security practices such as restricting access to the affected systems and monitoring for any suspicious activity.