A vulnerability has been identified in DIGSI 4 (All versions < V4.94 SP1 HF 1). Several folders in the %PATH% are writeable by normal users. As these folders are included in the search for dlls, an attacker could place dlls there with code executed by SYSTEM.
2021-02-09T17:15:13.687
2024-11-21T05:17:45.247
Modified
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | siemens | digsi_4 | < 4.94 | Yes |
Application | siemens | digsi_4 | 4.94 | Yes |
Application | siemens | digsi_4 | 4.94 | Yes |