ZeroHour

CVE-2020-25176

CVSS 3.1
9.8 critical
EPSS
6%p93
Published
()
Modified
Description

Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not checked for reserved characters, it is possible for a remote, unauthenticated attacker to traverse an application’s directory, which could lead to remote code execution.

Vendors
schneider-electricrockwellautomationxylem
Products
easergy t300 firmware, easergy c5 firmware, micom c264 firmware, pacis gtw firmware, saitel dp firmware, epas gtw firmware, saitel dr firmware, scd2200 firmware, aadvance controller, isagraf free runtime, isagraf runtime, micro810 firmware
Weakness
CWE-23, CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.