← Back

CVE-2020-25180

nvd nist
Published: Mar 18, 2022Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of encryption performed with a fixed key value using the tiny encryption algorithm (TEA) on an entered or saved password. A remote, unauthenticated attacker could pass their own encrypted password to the ISaGRAF 5 Runtime, which may result in information disclosure on the device.

Affected (22)

Easergy T300 Firmware
Easergy C5 Firmware
Micom C264 Firmware
Pacis Gtw Firmware
Saitel Dp Firmware
Epas Gtw Firmware
Saitel Dr Firmware
Scd2200 Firmware
Aadvance Controller
Isagraf Free Runtime
Isagraf Runtime
Micro810 Firmware
Micro820 Firmware
Micro830 Firmware
Micro850 Firmware
Micro870 Firmware
1 product
Multismart Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.7.1
Running on/withPlatform Versions
Schneider Electric
Easergy T300
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.1.0
Running on/withPlatform Versions
Schneider Electric
Easergy C5
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before d6.1
Running on/withPlatform Versions
Schneider Electric
Micom C264
All versions
Configuration D
5 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 5.1
Version 5.2
Version 6.1
Version 6.3
Version 6.3
Running on/withPlatform Versions
Schneider Electric
Pacis Gtw
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 11.06.21
Running on/withPlatform Versions
Schneider Electric
Saitel Dp
All versions
Configuration F
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 6.4
Version 6.4
Running on/withPlatform Versions
Schneider Electric
Epas Gtw
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 11.06.12
Running on/withPlatform Versions
Schneider Electric
Saitel Dr
All versions
Configuration H
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Up to 10024
Running on/withPlatform Versions
Schneider Electric
Cp 3
All versions
Schneider Electric
Mc 31
All versions
Configuration I
3 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.40
Up to 6.6.8
From 5.0 to 6.0
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Micro810
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Micro820
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Micro830
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Micro850
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Rockwellautomation
Micro870
All versions
Configuration O
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.2.0

References (8)

Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.