Vulnerability Description
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of encryption performed with a fixed key value using the tiny encryption algorithm (TEA) on an entered or saved password. A remote, unauthenticated attacker could pass their own encrypted password to the ISaGRAF 5 Runtime, which may result in information disclosure on the device.
Affected Platforms (CPE)
π»
Easergy T300 Firmware
<= 2.7.1π»
Easergy C5 Firmware
< 1.1.0π»
Micom C264 Firmware
< d6.1π»
Pacis Gtw Firmware
= 5.1π»
Pacis Gtw Firmware
= 5.2π»
Pacis Gtw Firmware
= 6.1π»
Pacis Gtw Firmware
= 6.3π»
Pacis Gtw Firmware
= 6.3π»
Saitel Dp Firmware
<= 11.06.21π»
Epas Gtw Firmware
= 6.4π»
Epas Gtw Firmware
= 6.4π»
Saitel Dr Firmware
<= 11.06.12π»
Scd2200 Firmware
<= 10024π¦
Aadvance Controller
<= 1.40π¦
Isagraf Free Runtime
<= 6.6.8π¦
Isagraf Runtime
>= 5.0 and < 6.0π»
Micro810 Firmware
All versionsπ»
Micro820 Firmware
All versionsπ»
Micro830 Firmware
All versionsπ»
Micro850 Firmware
All versionsπ»
Micro870 Firmware
All versionsπ»
Multismart Firmware
< 3.2.0