Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-25176


Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not checked for reserved characters, it is possible for a remote, unauthenticated attacker to traverse an application’s directory, which could lead to remote code execution.


Published

2022-03-18T18:15:09.060

Last Modified

2024-11-21T05:17:33.640

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.1 (CRITICAL)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Secondary
    CWE-23
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System schneider-electric easergy_t300_firmware ≤ 2.7.1 Yes
Hardware schneider-electric easergy_t300 - No
Operating System schneider-electric easergy_c5_firmware < 1.1.0 Yes
Hardware schneider-electric easergy_c5 - No
Operating System schneider-electric micom_c264_firmware < d6.1 Yes
Hardware schneider-electric micom_c264 - No
Operating System schneider-electric pacis_gtw_firmware 5.1 Yes
Operating System schneider-electric pacis_gtw_firmware 5.2 Yes
Operating System schneider-electric pacis_gtw_firmware 6.1 Yes
Operating System schneider-electric pacis_gtw_firmware 6.3 Yes
Operating System schneider-electric pacis_gtw_firmware 6.3 Yes
Hardware schneider-electric pacis_gtw - No
Operating System schneider-electric saitel_dp_firmware ≤ 11.06.21 Yes
Hardware schneider-electric saitel_dp - No
Operating System schneider-electric epas_gtw_firmware 6.4 Yes
Operating System schneider-electric epas_gtw_firmware 6.4 Yes
Hardware schneider-electric epas_gtw - No
Operating System schneider-electric saitel_dr_firmware ≤ 11.06.12 Yes
Hardware schneider-electric saitel_dr - No
Operating System schneider-electric scd2200_firmware ≤ 10024 Yes
Hardware schneider-electric cp-3 - No
Hardware schneider-electric mc-31 - No
Application rockwellautomation aadvance_controller ≤ 1.40 Yes
Application rockwellautomation isagraf_free_runtime ≤ 6.6.8 Yes
Application rockwellautomation isagraf_runtime < 6.0 Yes
Operating System rockwellautomation micro810_firmware - Yes
Hardware rockwellautomation micro810 - No
Operating System rockwellautomation micro820_firmware - Yes
Hardware rockwellautomation micro820 - No
Operating System rockwellautomation micro830_firmware - Yes
Hardware rockwellautomation micro830 - No
Operating System rockwellautomation micro850_firmware - Yes
Hardware rockwellautomation micro850 - No
Operating System rockwellautomation micro870_firmware - Yes
Hardware rockwellautomation micro870 - No
Operating System xylem multismart_firmware < 3.2.0 Yes

References