6.7

CVE-2020-25182

Rockwell Automation ISaGRAF5 Runtime Uncontrolled Search Path Element

Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries could allow a local, unauthenticated attacker to execute arbitrary code. This vulnerability only affects ISaGRAF Runtime when running on Microsoft Windows systems.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schneider-electricPacis Gtw Firmware Version5.1 SwPlatformwindows
   Schneider-electricPacis Gtw Version-
Schneider-electricPacis Gtw Firmware Version5.2 SwPlatformwindows
   Schneider-electricPacis Gtw Version-
Schneider-electricPacis Gtw Firmware Version6.1 SwPlatformwindows
   Schneider-electricPacis Gtw Version-
Schneider-electricPacis Gtw Firmware Version6.3 SwPlatformlinux
   Schneider-electricPacis Gtw Version-
Schneider-electricPacis Gtw Firmware Version6.3 SwPlatformwindows
   Schneider-electricPacis Gtw Version-
Schneider-electricSaitel Dp Firmware Version <= 11.06.21
   Schneider-electricSaitel Dp Version-
Schneider-electricEpas Gtw Firmware Version6.4 SwPlatformlinux
   Schneider-electricEpas Gtw Version-
Schneider-electricEpas Gtw Firmware Version6.4 SwPlatformwindows
   Schneider-electricEpas Gtw Version-
Schneider-electricSaitel Dr Firmware Version <= 11.06.12
   Schneider-electricSaitel Dr Version-
Schneider-electricScd2200 Firmware Version <= 10024
   Schneider-electricCp-3 Version-
   Schneider-electricMc-31 Version-
RockwellautomationIsagraf Free Runtime SwPlatformisagraf6_workbench Version <= 6.6.8
XylemMultismart Firmware Version < 3.2.0
RockwellautomationIsagraf Runtime SwPlatformwindows Version >= 5.0 < 6.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.022
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
ics-cert@hq.dhs.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.