First published: Tue Feb 09 2021(Updated: )
A vulnerability has been identified in DIGSI 4 (All versions < V4.94 SP1 HF 1). Several folders in the %PATH% are writeable by normal users. As these folders are included in the search for dlls, an attacker could place dlls there with code executed by SYSTEM.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Digsi 4 | <4.94 | |
Siemens Digsi 4 | =4.94 | |
Siemens Digsi 4 | =4.94-sp1 | |
Siemens DIGSI 4 SP1 HF 1 | <4.94 | 4.94 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-25245.
The severity of CVE-2020-25245 is high with a score of 7.8.
All versions of DIGSI 4 below V4.94 SP1 HF 1 are affected.
By placing malicious DLL files in the writable folders included in the search for DLLs, an attacker can execute code with SYSTEM privileges.
Yes, you can find more information about CVE-2020-25245 at the following references: [Siemens CERT Portal](https://cert-portal.siemens.com/productcert/pdf/ssa-536315.pdf) and [CISA ICS Advisories](https://us-cert.cisa.gov/ics/advisories/icsa-21-040-10).