CVE-2020-25237
published 2021-02-09CVE-2020-25237: A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1 Update 1), SINEMA Server (All versions < V14.0 SP2 Update 2). When uploading files to…
PriorityP261high8.1CVSS 3.1
AVNACLPRLUINSUCNIHAH
EPSS
20.62%
97.2th percentile
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1 Update 1), SINEMA Server (All versions < V14.0 SP2 Update 2). When uploading files to an affected system using a zip container, the system does not correctly check if the relative file path of the extracted files is still within the intended target directory. With this an attacker could create or overwrite arbitrary files on an affected system. This type of vulnerability is also known as 'Zip-Slip'. (ZDI-CAN-12054)
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | sinec_network_management_system | < 1.0 | 1.0 |
| siemens | sinec_network_management_system | — | — |
| siemens | sinec_nms | — | — |
| siemens | sinema_server | < 14.0 | 14.0 |
| siemens | sinema_server | — | — |
| siemens | sinema_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Zip-Slip path traversal: monitor file upload endpoints on SINEC NMS / SINEMA Server for zip containers whose extracted entries contain relative path sequences (e.g., '../') that resolve outside the intended target directory ↗
- →Alert on arbitrary file creation or overwrite events on SINEC NMS / SINEMA Server hosts following a zip file upload, as successful exploitation results in creation or overwrite of arbitrary files which can lead to code execution ↗
- →This vulnerability is exploitable remotely with low skill level and low privilege (CVSS PR:L), so monitor for authenticated low-privilege users performing file upload operations on the affected products ↗
- ·No known public exploits specifically target this vulnerability at time of advisory publication ↗
- ·Affected versions are SINEC NMS all versions prior to v1.0 SP1 Update 1, and SINEMA Server all versions prior to v14.0 SP2 Update 2; patched versions are not vulnerable ↗
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SINEMA Server & SINEC NMS
cisa_ics·2021-02-09·CVSS 8.1
[HIGH] Siemens SINEMA Server & SINEC NMS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEMA Server & SINEC NMS
Last RevisedFebruary 09, 2021
Alert CodeICSA-21-040-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Siemens
- Equipment: SINEMA Server, SINEC NMS
- Vulnerability: Path Traversal
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow arbitrary code execution on an affected system.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Siemens products, are affected:
- SINEC NMS: All versions prior to v1.0 SP1 Update 1
- SINEMA S
GHSA
GHSA-3xq9-pprq-hm99: A vulnerability has been identified in SINEC NMS (All versions < V1
ghsa_unreviewed·2022-05-24
CVE-2020-25237 [HIGH] CWE-22 GHSA-3xq9-pprq-hm99: A vulnerability has been identified in SINEC NMS (All versions < V1
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1 Update 1), SINEMA Server (All versions < V14.0 SP2 Update 2). When uploading files to an affected system using a zip container, the system does not correctly check if the relative file path of the extracted files is still within the intended target directory. With this an attacker could create or overwrite arbitrary files on an affected system. This type of vulnerability is also known as 'Zip-Slip'. (ZDI-CAN-12054)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-156833.pdfhttps://us-cert.cisa.gov/ics/advisories/icsa-21-040-03https://www.zerodayinitiative.com/advisories/ZDI-21-253/https://cert-portal.siemens.com/productcert/pdf/ssa-156833.pdfhttps://us-cert.cisa.gov/ics/advisories/icsa-21-040-03https://www.zerodayinitiative.com/advisories/ZDI-21-253/
2021-02-09
Published