PT-2021-11123 · Siemens · Logo! Soft Comfort

Published

2021-04-22

·

Updated

2023-12-12

·

CVE-2020-25243

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: LOGO! Soft Comfort versions prior to V8.4
Description: A zip slip vulnerability could be triggered while importing a compromised project file to the affected software. This issue could ultimately lead to a system takeover by an attacker if chained with other vulnerabilities.
Recommendations: For versions prior to V8.4, update to version V8.4 or later to resolve the issue. As a temporary workaround, consider avoiding the import of project files from untrusted sources until a patch is applied. Restrict access to the project file import feature to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2020-25243

Affected Products

Logo! Soft Comfort