CVE-2020-25245: High severity siemens digsi 4 vulnerability
A vulnerability has been identified in DIGSI 4 (All versions < V4.94 SP1 HF 1). Several folders in the %PATH% are writeable by normal users. As these folders are included in the search for dlls, an attacker could place dlls there with code executed by SYSTEM.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-25245.
What is the severity of CVE-2020-25245?
The severity of CVE-2020-25245 is high with a score of 7.8.
Which software versions are affected by CVE-2020-25245?
All versions of DIGSI 4 below V4.94 SP1 HF 1 are affected.
How can an attacker exploit CVE-2020-25245?
By placing malicious DLL files in the writable folders included in the search for DLLs, an attacker can execute code with SYSTEM privileges.
Are there any references for CVE-2020-25245?
Yes, you can find more information about CVE-2020-25245 at the following references: [Siemens CERT Portal](https://cert-portal.siemens.com/productcert/pdf/ssa-536315.pdf) and [CISA ICS Advisories](https://us-cert.cisa.gov/ics/advisories/icsa-21-040-10).