CVE-2020-25243
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). A zip slip vulnerability could be triggered while importing a compromised project file
to the affected software. Chained with other vulnerabilities this vulnerability could
ultimately lead to a system takeover by an attacker.
Se ha identificado una vulnerabilidad en LOGO! Soft Comfort (todas las versiones). Podría ser desencadenada una vulnerabilidad de zip slip mientras se importa un archivo de proyecto comprometido al software afectado. Encadenada con otras vulnerabilidades, esta vulnerabilidad podría, en última instancia, conllevar a un atacante a tomar el control del sistema
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). A zip slip vulnerability could be triggered while importing a compromised project file to the affected software. Chained with other vulnerabilities this vulnerability could ultimately lead to a system takeover by an attacker.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2020-09-10 CVE Reserved
- 2021-04-22 CVE Published
- 2024-11-19 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-983300.pdf | 2023-12-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Logo\! Soft Comfort Search vendor "Siemens" for product "Logo\! Soft Comfort" | * | - |
Affected
|