VDB
CVE-2020-25237
CVE-2020-25237
PUBLISHED
CVSS 8.100000381469727 HIGH
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1 Update 1), SINEMA Server (All versions < V14.0 SP2 Update 2). When uploading files to an affected system using a zip container, the system does not correctly check if the relative file path of the extracted files is still within the intended target directory. With this an attacker could create or overwrite arbitrary files on an affected system. This type of vulnerability is also known as 'Zip-Slip'. (ZDI-CAN-12054)
EPSS 2.82% · 86.5th percentile
Risk Scores
CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
EPSS Score
2.82%
86.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | SINEC NMS | All versions < V1.0 SP1 Update 1 |
| Siemens | SINEMA Server | * |
| siemens | sinec_network_management_system | 1.0, 1.0, 0 |
| siemens | sinema_server | 14.0, 14.0, 14.0 |
Exploit Intelligence
Timeline
- Feb 9, 2021 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-663999.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-541017.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-944678.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-156833.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-536315.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-362164.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-428051.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-794542.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-686152.pdf advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-040-03 url
- https://www.zerodayinitiative.com/advisories/ZDI-21-253/ url
- https://nvd.nist.gov/vuln/detail/CVE-2020-25237 advisory
- https://www.zerodayinitiative.com/advisories/ZDI-21-253 url