CVE-2020-25176
9.1
CRITICAL · CVSS 3.1 · EPSS 6.4% (pctl 94)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not checked for reserved characters, it is possible for a remote, unauthenticated attacker to traverse an application’s directory, which could lead to remote code execution.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 6.42% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-23 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-03-18 |
| Last modified | 2026-06-17 |
Affected (31)
| Vendor | Product |
|---|---|
| rockwellautomation | aadvance controller |
| rockwellautomation | isagraf free runtime |
| rockwellautomation | isagraf runtime |
| rockwellautomation | micro810 |
| rockwellautomation | micro810 firmware |
| rockwellautomation | micro820 |
| rockwellautomation | micro820 firmware |
| rockwellautomation | micro830 |
| rockwellautomation | micro830 firmware |
| rockwellautomation | micro850 |
| rockwellautomation | micro850 firmware |
| rockwellautomation | micro870 |
| rockwellautomation | micro870 firmware |
| schneider-electric | cp-3 |
| schneider-electric | easergy c5 |
| schneider-electric | easergy c5 firmware |
| schneider-electric | easergy t300 |
| schneider-electric | easergy t300 firmware |
| schneider-electric | epas gtw |
| schneider-electric | epas gtw firmware |
| schneider-electric | mc-31 |
| schneider-electric | micom c264 |
| schneider-electric | micom c264 firmware |
| schneider-electric | pacis gtw |
| schneider-electric | pacis gtw firmware |
| schneider-electric | saitel dp |
| schneider-electric | saitel dp firmware |
| schneider-electric | saitel dr |
| schneider-electric | saitel dr firmware |
| schneider-electric | scd2200 firmware |
| xylem | multismart firmware |
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-04
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1131699
- https://www.cisa.gov/uscert/ics/advisories/icsa-20-280-01
- https://www.xylem.com/siteassets/about-xylem/cybersecurity/advisories/xylem-multismart-rockwell-isagraf.pdf
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-04
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1131699
- https://www.cisa.gov/uscert/ics/advisories/icsa-20-280-01
- https://www.xylem.com/siteassets/about-xylem/cybersecurity/advisories/xylem-multismart-rockwell-isagraf.pdf
→ the Explorer · watch your stack · NVD