Today, Siemens published an out-of-zone advisory that discusses a path traversal vulnerability in their SiPass integrated product. This is a third-party (DotNetZip) vulnerability. Siemens has new versions that mitigate the vulnerability.
The DotNetZip vulnerability was reported by Thomas Chauchefoin of Bentley Systems. He reports that:
“DotNetZip is affec…
Keep reading with a 7-day free trial
Subscribe to CFSN Detailed Analysis to keep reading this post and get 7 days of free access to the full post archives.