PT-2021-11124 · Siemens · Logo! Soft Comfort

Published

2021-04-22

·

Updated

2023-12-12

·

CVE-2020-25244

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: LOGO! Soft Comfort versions prior to V8.4
Description: A security issue has been identified in the software, where it insecurely loads libraries, making it susceptible to DLL hijacking. This could allow a local attacker to successfully exploit the issue and potentially take over the system where the software is installed.
Recommendations: For versions prior to V8.4, update to version V8.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the system where the software is installed to minimize the risk of exploitation.

Fix

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2020-25244

Affected Products

Logo! Soft Comfort