CyberSec.Space Logo
Back to CVE Browser

CVE-2020-25180

MEDIUM
5.3
CVSS Severity Score
EPSS Score0.1280%
EPSS Percentile4.38th
PublishedMar 18, 2022
Last ModifiedNov 21, 2024

Vulnerability Description

Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of encryption performed with a fixed key value using the tiny encryption algorithm (TEA) on an entered or saved password. A remote, unauthenticated attacker could pass their own encrypted password to the ISaGRAF 5 Runtime, which may result in information disclosure on the device.

Affected Platforms (CPE)

πŸ’»
Schneider Electric

Easergy T300 Firmware

<= 2.7.1
πŸ’»
Schneider Electric

Easergy C5 Firmware

< 1.1.0
πŸ’»
Schneider Electric

Micom C264 Firmware

< d6.1
πŸ’»
Schneider Electric

Pacis Gtw Firmware

= 5.1
πŸ’»
Schneider Electric

Pacis Gtw Firmware

= 5.2
πŸ’»
Schneider Electric

Pacis Gtw Firmware

= 6.1
πŸ’»
Schneider Electric

Pacis Gtw Firmware

= 6.3
πŸ’»
Schneider Electric

Pacis Gtw Firmware

= 6.3
πŸ’»
Schneider Electric

Saitel Dp Firmware

<= 11.06.21
πŸ’»
Schneider Electric

Epas Gtw Firmware

= 6.4
πŸ’»
Schneider Electric

Epas Gtw Firmware

= 6.4
πŸ’»
Schneider Electric

Saitel Dr Firmware

<= 11.06.12
πŸ’»
Schneider Electric

Scd2200 Firmware

<= 10024
πŸ“¦
Rockwellautomation

Aadvance Controller

<= 1.40
πŸ“¦
Rockwellautomation

Isagraf Free Runtime

<= 6.6.8
πŸ“¦
Rockwellautomation

Isagraf Runtime

>= 5.0 and < 6.0
πŸ’»
Rockwellautomation

Micro810 Firmware

All versions
πŸ’»
Rockwellautomation

Micro820 Firmware

All versions
πŸ’»
Rockwellautomation

Micro830 Firmware

All versions
πŸ’»
Rockwellautomation

Micro850 Firmware

All versions
πŸ’»
Rockwellautomation

Micro870 Firmware

All versions
πŸ’»
Xylem

Multismart Firmware

< 3.2.0

References & Advisories

Related Vulnerabilities

CVE-2020-25180 Detail & Impact Analysis | CVSS 5.3 (MEDIUM) | Cyber-Sec.Space | Cyber-Sec.Space