CVE-2020-25244 is a vulnerability in Siemens Logo Soft Comfort
Published on April 22, 2021
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). The software insecurely loads libraries which makes it vulnerable to DLL hijacking. Successful exploitation by a local attacker could lead to a takeover of the system where the software is installed.
Weakness Type
What is a DLL preloading Vulnerability?
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
CVE-2020-25244 has been classified to as a DLL preloading vulnerability or weakness.
Products Associated with CVE-2020-25244
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2020-25244 are published in Siemens Logo Soft Comfort:
Affected Versions
Siemens LOGO! Soft Comfort Version All versions < V8.4 is affected by CVE-2020-25244Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.