High severity7.8NVD Advisory· Published Feb 9, 2021· Updated Jun 17, 2026
CVE-2020-25245
CVE-2020-25245
Description
A vulnerability has been identified in DIGSI 4 (All versions < V4.94 SP1 HF 1). Several folders in the %PATH% are writeable by normal users. As these folders are included in the search for dlls, an attacker could place dlls there with code executed by SYSTEM.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:siemens:digsi_4:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:siemens:digsi_4:*:*:*:*:*:*:*:*range: <4.94
- cpe:2.3:a:siemens:digsi_4:4.94:-:*:*:*:*:*:*
- cpe:2.3:a:siemens:digsi_4:4.94:sp1:*:*:*:*:*:*
- (no CPE)range: <V4.94 SP1 HF 1
- (no CPE)range: All versions < V4.94 SP1 HF 1
Patches
Vulnerability mechanics
References
2- us-cert.cisa.gov/ics/advisories/icsa-21-040-10nvdPatchThird Party AdvisoryUS Government Resource
- cert-portal.siemens.com/productcert/pdf/ssa-536315.pdfnvdVendor Advisory
News mentions
0No linked articles in our index yet.