cbcvebase.
CVE-2020-25184
published 2022-03-18

CVE-2020-25184: Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file…

medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable without any additional modification. A local, unauthenticated attacker could compromise the user passwords, resulting in information disclosure.

Affected

17 ranges
VendorProductVersion rangeFixed in
rockwell_automationisagraf_runtime
rockwell_automationisagraf_runtime
rockwellautomationaadvance_controller<= 1.40
rockwellautomationisagraf_free_runtime<= 6.6.8
rockwellautomationisagraf_runtime>= 5.0 < 6.06.0
schneider-electriceasergy_c5_firmware< 1.1.01.1.0
schneider-electriceasergy_t300_firmware<= 2.7.1
schneider-electricepas_gtw_firmware
schneider-electricmicom_c264_firmware< d6.1d6.1
schneider-electricpacis_gtw_firmware
schneider-electricpacis_gtw_firmware
schneider-electricpacis_gtw_firmware
schneider-electricpacis_gtw_firmware
schneider-electricsaitel_dp_firmware<= 11.06.21
schneider-electricsaitel_dr_firmware<= 11.06.12
schneider-electricscd2200_firmware<= 10024
xylemmultismart_firmware< 3.2.03.2.0