cbcvebase.
CVE-2020-25176
published 2022-03-18

CVE-2020-25176: Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file…

PriorityP267critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.21%
92.7th percentile
Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not checked for reserved characters, it is possible for a remote, unauthenticated attacker to traverse an application’s directory, which could lead to remote code execution.

Affected

17 ranges
VendorProductVersion rangeFixed in
rockwell_automationisagraf_runtime
rockwell_automationisagraf_runtime
rockwellautomationaadvance_controller<= 1.40
rockwellautomationisagraf_free_runtime<= 6.6.8
rockwellautomationisagraf_runtime>= 5.0 < 6.06.0
schneider-electriceasergy_c5_firmware< 1.1.01.1.0
schneider-electriceasergy_t300_firmware<= 2.7.1
schneider-electricepas_gtw_firmware
schneider-electricmicom_c264_firmware< d6.1d6.1
schneider-electricpacis_gtw_firmware
schneider-electricpacis_gtw_firmware
schneider-electricpacis_gtw_firmware
schneider-electricpacis_gtw_firmware
schneider-electricsaitel_dp_firmware<= 11.06.21
schneider-electricsaitel_dr_firmware<= 11.06.12
schneider-electricscd2200_firmware<= 10024
xylemmultismart_firmware< 3.2.03.2.0

Detection & IOCsextracted from sources · hover to see the quote

portTCP 1131
portTCP 1132
  • Alert on unexpected file creation, modification, or deletion in the ISaGRAF Runtime application directory, which may indicate successful directory traversal and remote code execution.
  • ·The vulnerability affects all ISaGRAF Runtime Versions 4.x and 5.x; patched version is ISaGRAF Runtime 5 Version 5.72.00. Detection logic should account for unpatched legacy deployments across multiple OEM products.
  • ·Multiple third-party OEM products embed the vulnerable ISaGRAF runtime (AADvance Controller, Micro800, GE ALSPA S6 MFC3000/MFC1000, Xylem MultiSmart Gen-1/Gen-2), broadening the attack surface beyond Rockwell-branded devices.
  • ·The IXL protocol transmits data unencrypted over TCP, meaning network-based detection (e.g., IDS/IPS) can inspect plaintext IXL traffic for traversal payloads without needing decryption.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.