ZeroHour

CVE-2020-25180

CVSS 3.1
6.5 medium
EPSS
1%p65
Published
()
Modified
Description

Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of encryption performed with a fixed key value using the tiny encryption algorithm (TEA) on an entered or saved password. A remote, unauthenticated attacker could pass their own encrypted password to the ISaGRAF 5 Runtime, which may result in information disclosure on the device.

Vendors
schneider-electricrockwellautomationxylem
Products
easergy t300 firmware, easergy c5 firmware, micom c264 firmware, pacis gtw firmware, saitel dp firmware, epas gtw firmware, saitel dr firmware, scd2200 firmware, aadvance controller, isagraf free runtime, isagraf runtime, micro810 firmware
Weakness
CWE-321, CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.