peter bassill · operator
$ cve CVE-2020-25176 JSON

CVE-2020-25176

9.1
CRITICAL · CVSS 3.1 · EPSS 6.4% (pctl 94)

In your normal cycle

Critical by CVSS (9.1), but no sign of active exploitation.

Description

Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not checked for reserved characters, it is possible for a remote, unauthenticated attacker to traverse an application’s directory, which could lead to remote code execution.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS6.42% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-23
On CISA KEVno
Public exploitnone known
Published2022-03-18
Last modified2026-06-17

Affected (31)

VendorProduct
rockwellautomationaadvance controller
rockwellautomationisagraf free runtime
rockwellautomationisagraf runtime
rockwellautomationmicro810
rockwellautomationmicro810 firmware
rockwellautomationmicro820
rockwellautomationmicro820 firmware
rockwellautomationmicro830
rockwellautomationmicro830 firmware
rockwellautomationmicro850
rockwellautomationmicro850 firmware
rockwellautomationmicro870
rockwellautomationmicro870 firmware
schneider-electriccp-3
schneider-electriceasergy c5
schneider-electriceasergy c5 firmware
schneider-electriceasergy t300
schneider-electriceasergy t300 firmware
schneider-electricepas gtw
schneider-electricepas gtw firmware
schneider-electricmc-31
schneider-electricmicom c264
schneider-electricmicom c264 firmware
schneider-electricpacis gtw
schneider-electricpacis gtw firmware
schneider-electricsaitel dp
schneider-electricsaitel dp firmware
schneider-electricsaitel dr
schneider-electricsaitel dr firmware
schneider-electricscd2200 firmware
xylemmultismart firmware

References

→ the Explorer  ·  watch your stack  ·  NVD