9.3

CVE-2020-25178

ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Data is transferred over this protocol unencrypted, which could allow a remote unauthenticated attacker to upload, read, and delete files.

Data is provided by the National Vulnerability Database (NVD)
Schneider-electricPacis Gtw Firmware Version5.1 SwPlatformwindows
   Schneider-electricPacis Gtw Version-
Schneider-electricPacis Gtw Firmware Version5.2 SwPlatformwindows
   Schneider-electricPacis Gtw Version-
Schneider-electricPacis Gtw Firmware Version6.1 SwPlatformwindows
   Schneider-electricPacis Gtw Version-
Schneider-electricPacis Gtw Firmware Version6.3 SwPlatformlinux
   Schneider-electricPacis Gtw Version-
Schneider-electricPacis Gtw Firmware Version6.3 SwPlatformwindows
   Schneider-electricPacis Gtw Version-
Schneider-electricSaitel Dp Firmware Version <= 11.06.21
   Schneider-electricSaitel Dp Version-
Schneider-electricEpas Gtw Firmware Version6.4 SwPlatformlinux
   Schneider-electricEpas Gtw Version-
Schneider-electricEpas Gtw Firmware Version6.4 SwPlatformwindows
   Schneider-electricEpas Gtw Version-
Schneider-electricSaitel Dr Firmware Version <= 11.06.12
   Schneider-electricSaitel Dr Version-
Schneider-electricScd2200 Firmware Version <= 10024
   Schneider-electricCp-3 Version-
   Schneider-electricMc-31 Version-
RockwellautomationIsagraf Free Runtime SwPlatformisagraf6_workbench Version <= 6.6.8
RockwellautomationIsagraf Runtime Version >= 5.0 < 6.0
XylemMultismart Firmware Version < 3.2.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.23% 0.457
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
ics-cert@hq.dhs.gov 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-319 Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.