cbcvebase.
CVE-2020-25237
published 2021-02-09

CVE-2020-25237: A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1 Update 1), SINEMA Server (All versions < V14.0 SP2 Update 2). When uploading files to…

PriorityP261high8.1CVSS 3.1
AVNACLPRLUINSUCNIHAH
EPSS
20.62%
97.2th percentile
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1 Update 1), SINEMA Server (All versions < V14.0 SP2 Update 2). When uploading files to an affected system using a zip container, the system does not correctly check if the relative file path of the extracted files is still within the intended target directory. With this an attacker could create or overwrite arbitrary files on an affected system. This type of vulnerability is also known as 'Zip-Slip'. (ZDI-CAN-12054)

Affected

6 ranges
VendorProductVersion rangeFixed in
siemenssinec_network_management_system< 1.01.0
siemenssinec_network_management_system
siemenssinec_nms
siemenssinema_server< 14.014.0
siemenssinema_server
siemenssinema_server

Detection & IOCsextracted from sources · hover to see the quote

  • Zip-Slip path traversal: monitor file upload endpoints on SINEC NMS / SINEMA Server for zip containers whose extracted entries contain relative path sequences (e.g., '../') that resolve outside the intended target directory
  • Alert on arbitrary file creation or overwrite events on SINEC NMS / SINEMA Server hosts following a zip file upload, as successful exploitation results in creation or overwrite of arbitrary files which can lead to code execution
  • This vulnerability is exploitable remotely with low skill level and low privilege (CVSS PR:L), so monitor for authenticated low-privilege users performing file upload operations on the affected products
  • ·No known public exploits specifically target this vulnerability at time of advisory publication
  • ·Affected versions are SINEC NMS all versions prior to v1.0 SP1 Update 1, and SINEMA Server all versions prior to v14.0 SP2 Update 2; patched versions are not vulnerable

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.