CVE-2020-25176
published 2022-03-18CVE-2020-25176: Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file…
PriorityP267critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.21%
92.7th percentile
Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not checked for reserved characters, it is possible for a remote, unauthenticated attacker to traverse an application’s directory, which could lead to remote code execution.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| rockwell_automation | isagraf_runtime | — | — |
| rockwell_automation | isagraf_runtime | — | — |
| rockwellautomation | aadvance_controller | <= 1.40 | — |
| rockwellautomation | isagraf_free_runtime | <= 6.6.8 | — |
| rockwellautomation | isagraf_runtime | >= 5.0 < 6.0 | 6.0 |
| schneider-electric | easergy_c5_firmware | < 1.1.0 | 1.1.0 |
| schneider-electric | easergy_t300_firmware | <= 2.7.1 | — |
| schneider-electric | epas_gtw_firmware | — | — |
| schneider-electric | micom_c264_firmware | < d6.1 | d6.1 |
| schneider-electric | pacis_gtw_firmware | — | — |
| schneider-electric | pacis_gtw_firmware | — | — |
| schneider-electric | pacis_gtw_firmware | — | — |
| schneider-electric | pacis_gtw_firmware | — | — |
| schneider-electric | saitel_dp_firmware | <= 11.06.21 | — |
| schneider-electric | saitel_dr_firmware | <= 11.06.12 | — |
| schneider-electric | scd2200_firmware | <= 10024 | — |
| xylem | multismart_firmware | < 3.2.0 | 3.2.0 |
Detection & IOCsextracted from sources · hover to see the quote
- →Alert on unexpected file creation, modification, or deletion in the ISaGRAF Runtime application directory, which may indicate successful directory traversal and remote code execution. ↗
- ·The vulnerability affects all ISaGRAF Runtime Versions 4.x and 5.x; patched version is ISaGRAF Runtime 5 Version 5.72.00. Detection logic should account for unpatched legacy deployments across multiple OEM products. ↗
- ·Multiple third-party OEM products embed the vulnerable ISaGRAF runtime (AADvance Controller, Micro800, GE ALSPA S6 MFC3000/MFC1000, Xylem MultiSmart Gen-1/Gen-2), broadening the attack surface beyond Rockwell-branded devices. ↗
- ·The IXL protocol transmits data unencrypted over TCP, meaning network-based detection (e.g., IDS/IPS) can inspect plaintext IXL traffic for traversal payloads without needing decryption. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation ISaGRAF5 Runtime (Update A)
cisa_ics·2021-06-17
Rockwell Automation ISaGRAF5 Runtime (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation ISaGRAF5 Runtime (Update A)
Last RevisedJune 17, 2021
Alert CodeICSA-20-280-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.1
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Rockwell Automation
- Equipment: ISaGRAF5 Runtime
- Vulnerabilities: Use of Hard-coded Cryptographic Key, Unprotected Storage of Credentials, Relative Path Traversal, Uncontrolled Search Path Element, Cleartext Transmission of Sensitive Information\
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the portal-to-web advisory titled ICSA-20-280-01P Rockwell Au
GHSA
GHSA-fg53-m5qv-8qwq: Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4
ghsa_unreviewed·2022-03-19
CVE-2020-25176 [CRITICAL] CWE-22 GHSA-fg53-m5qv-8qwq: Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4
Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not checked for reserved characters, it is possible for a remote, unauthenticated attacker to traverse an application’s directory, which could lead to remote code execution.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-04https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1131699https://www.cisa.gov/uscert/ics/advisories/icsa-20-280-01https://www.xylem.com/siteassets/about-xylem/cybersecurity/advisories/xylem-multismart-rockwell-isagraf.pdfhttps://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-04https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1131699https://www.cisa.gov/uscert/ics/advisories/icsa-20-280-01https://www.xylem.com/siteassets/about-xylem/cybersecurity/advisories/xylem-multismart-rockwell-isagraf.pdf
2022-03-18
Published