CVE-2020-25245
 
Severity Score
7.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
A vulnerability has been identified in DIGSI 4 (All versions < V4.94 SP1 HF 1). Several folders in the %PATH% are writeable by normal users. As these folders are included in the search for dlls, an attacker could place dlls there with code executed by SYSTEM.
Se ha identificado una vulnerabilidad en DIGSI 4 (Todas las versiones anteriores a V4.94 SP1 HF 1). Los usuarios normales pueden escribir varias carpetas en el %PATH%. Como estas carpetas se incluyen en la búsqueda de dlls, un atacante podría colocar dlls allí con código ejecutado por SYSTEM
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2020-09-10 CVE Reserved
- 2021-02-09 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-276: Incorrect Default Permissions
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-21-040-10 | 2021-02-25 |
URL | Date | SRC |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-536315.pdf | 2021-02-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Digsi 4 Search vendor "Siemens" for product "Digsi 4" | < 4.94 Search vendor "Siemens" for product "Digsi 4" and version " < 4.94" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Digsi 4 Search vendor "Siemens" for product "Digsi 4" | 4.94 Search vendor "Siemens" for product "Digsi 4" and version "4.94" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Digsi 4 Search vendor "Siemens" for product "Digsi 4" | 4.94 Search vendor "Siemens" for product "Digsi 4" and version "4.94" | sp1 |
Affected
|