A vulnerability has been identified in DIGSI 4 (All versions < V4.94 SP1 HF 1). Several folders in the %PATH% are writeable by normal users. As these folders are included in the search for dlls, an attacker could place dlls there with code executed by SYSTEM.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-536315.pdf | vendor advisory |
https://us-cert.cisa.gov/ics/advisories/icsa-21-040-10 | patch third party advisory us government resource |