VYPR
Unrated severityNVD Advisory· Published Feb 9, 2021· Updated Aug 4, 2024

CVE-2020-25245

CVE-2020-25245

Description

A vulnerability has been identified in DIGSI 4 (All versions < V4.94 SP1 HF 1). Several folders in the %PATH% are writeable by normal users. As these folders are included in the search for dlls, an attacker could place dlls there with code executed by SYSTEM.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

DIGSI 4 versions prior to V4.94 SP1 HF 1 allow low-privileged users to plant malicious DLLs in writable %PATH% folders, leading to arbitrary code execution as SYSTEM.

Vulnerability

The vulnerability is an incorrect default permissions issue (CWE-276) in Siemens DIGSI 4. Several folders in the %PATH% environment variable are writable by normal users. Since these folders are included in the search order for DLLs, an attacker can place a malicious DLL in one of these directories. Affected versions: all versions prior to V4.94 SP1 HF 1. [1]

Exploitation

An attacker needs low-privileged local access to the system. No user interaction is required beyond the attacker placing the DLL. The attacker can write a specially crafted DLL into a writable folder that is part of the %PATH%. When a privileged process (running as SYSTEM) loads a DLL from that path, the malicious DLL is executed instead. [1]

Impact

Successful exploitation allows the attacker to execute arbitrary code with SYSTEM privileges, leading to full compromise of confidentiality, integrity, and availability. The CVSS v3 base score is 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). [1]

Mitigation

Siemens has released an update: upgrade to DIGSI 4 v4.94 SP1 HF 1 or later. As a general security measure, Siemens recommends protecting network access and configuring the environment according to industrial security guidelines. [1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Siemens Foundation/DIGSI 4llm-fuzzy2 versions
    < V4.94 SP1 HF 1+ 1 more
    • (no CPE)range: < V4.94 SP1 HF 1
    • (no CPE)range: All versions < V4.94 SP1 HF 1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.