6.7
CVE-2020-25182
- EPSS 0.45%
- Veröffentlicht 18.03.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:17:34
- Erkennungen
Rockwell Automation ISaGRAF5 Runtime Uncontrolled Search Path Element
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries could allow a local, unauthenticated attacker to execute arbitrary code. This vulnerability only affects ISaGRAF Runtime when running on Microsoft Windows systems.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schneider-electric ≫ Easergy T300 Firmware Version <= 2.7.1
Schneider-electric ≫ Easergy C5 Firmware Version < 1.1.0
Schneider-electric ≫ Micom C264 Firmware Version < d6.1
Schneider-electric ≫ Pacis Gtw Firmware Version 5.1 SwPlatform windows
Schneider-electric ≫ Pacis Gtw Firmware Version 5.2 SwPlatform windows
Schneider-electric ≫ Pacis Gtw Firmware Version 6.1 SwPlatform windows
Schneider-electric ≫ Pacis Gtw Firmware Version 6.3 SwPlatform linux
Schneider-electric ≫ Pacis Gtw Firmware Version 6.3 SwPlatform windows
Schneider-electric ≫ Saitel Dp Firmware Version <= 11.06.21
Schneider-electric ≫ Epas Gtw Firmware Version 6.4 SwPlatform linux
Schneider-electric ≫ Epas Gtw Firmware Version 6.4 SwPlatform windows
Schneider-electric ≫ Saitel Dr Firmware Version <= 11.06.12
Schneider-electric ≫ Scd2200 Firmware Version <= 10024
Rockwellautomation ≫ Aadvance Controller Version <= 1.40
Rockwellautomation ≫ Isagraf Free Runtime SwPlatform isagraf6_workbench Version <= 6.6.8
Rockwellautomation ≫ Micro810 Firmware Version -
Rockwellautomation ≫ Micro820 Firmware Version -
Rockwellautomation ≫ Micro830 Firmware Version -
Rockwellautomation ≫ Micro850 Firmware Version -
Rockwellautomation ≫ Micro870 Firmware Version -
Xylem ≫ Multismart Firmware Version < 3.2.0
Rockwellautomation ≫ Isagraf Runtime SwPlatform windows Version >= 5.0 < 6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.45% | 0.371 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
| DHS.gov | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-427 Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-04
https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1131699
https://www.cisa.gov/uscert/ics/advisories/icsa-20-280-01
https://www.xylem.com/siteassets/about-xylem/cybersecurity/advisories/xylem-multismart-rockwell-isagraf.pdf