ZeroHour

CVE-2020-25178

CVSS 3.1
8.8 high
EPSS
2%p76
Published
()
Modified
Description

ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Data is transferred over this protocol unencrypted, which could allow a remote unauthenticated attacker to upload, read, and delete files.

Vendors
schneider-electricrockwellautomationxylem
Products
easergy t300 firmware, easergy c5 firmware, micom c264 firmware, pacis gtw firmware, saitel dp firmware, epas gtw firmware, saitel dr firmware, scd2200 firmware, aadvance controller, isagraf free runtime, isagraf runtime, micro810 firmware
Weakness
CWE-319
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.