Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of encryption performed with a fixed key value using the tiny encryption algorithm (TEA) on an entered or saved password. A remote, unauthenticated attacker could pass their own encrypted password to the ISaGRAF 5 Runtime, which may result in information disclosure on the device.
References
Link | Resource |
---|---|
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-04 | Vendor Advisory |
https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1131699 | Permissions Required |
https://www.cisa.gov/uscert/ics/advisories/icsa-20-280-01 | Third Party Advisory US Government Resource |
https://www.xylem.com/siteassets/about-xylem/cybersecurity/advisories/xylem-multismart-rockwell-isagraf.pdf | Third Party Advisory |
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-04 | Vendor Advisory |
https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1131699 | Permissions Required |
https://www.cisa.gov/uscert/ics/advisories/icsa-20-280-01 | Third Party Advisory US Government Resource |
https://www.xylem.com/siteassets/about-xylem/cybersecurity/advisories/xylem-multismart-rockwell-isagraf.pdf | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
Configuration 14 (hide)
AND |
|
Configuration 15 (hide)
|
History
21 Nov 2024, 05:17
Type | Values Removed | Values Added |
---|---|---|
References | () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-04 - Vendor Advisory | |
References | () https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1131699 - Permissions Required | |
References | () https://www.cisa.gov/uscert/ics/advisories/icsa-20-280-01 - Third Party Advisory, US Government Resource | |
References | () https://www.xylem.com/siteassets/about-xylem/cybersecurity/advisories/xylem-multismart-rockwell-isagraf.pdf - Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : 4.3
v3 : 5.3 |
04 Apr 2022, 20:59
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-798 | |
CPE | cpe:2.3:h:rockwellautomation:micro870:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:easergy_t300:-:*:*:*:*:*:*:* cpe:2.3:h:rockwellautomation:micro820:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:saitel_dp_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:micom_c264_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:scd2200_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:pacis_gtw_firmware:6.1:*:*:*:*:windows:*:* cpe:2.3:o:xylem:multismart_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:epas_gtw:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:micom_c264:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:easergy_c5:-:*:*:*:*:*:*:* cpe:2.3:a:rockwellautomation:isagraf_free_runtime:*:*:*:*:*:isagraf6_workbench:*:* cpe:2.3:h:schneider-electric:mc-31:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:epas_gtw_firmware:6.4:*:*:*:*:linux:*:* cpe:2.3:o:schneider-electric:saitel_dr_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:easergy_c5_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:epas_gtw_firmware:6.4:*:*:*:*:windows:*:* cpe:2.3:h:schneider-electric:cp-3:-:*:*:*:*:*:*:* cpe:2.3:o:rockwellautomation:micro820_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:rockwellautomation:micro810:-:*:*:*:*:*:*:* cpe:2.3:o:rockwellautomation:micro810_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:pacis_gtw_firmware:5.2:*:*:*:*:windows:*:* cpe:2.3:h:rockwellautomation:micro850:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:pacis_gtw_firmware:6.3:*:*:*:*:linux:*:* cpe:2.3:h:rockwellautomation:micro830:-:*:*:*:*:*:*:* cpe:2.3:o:rockwellautomation:micro850_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:pacis_gtw:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:saitel_dp:-:*:*:*:*:*:*:* cpe:2.3:a:rockwellautomation:isagraf_runtime:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:easergy_t300_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:rockwellautomation:micro830_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:pacis_gtw_firmware:5.1:*:*:*:*:windows:*:* cpe:2.3:o:rockwellautomation:micro870_firmware:-:*:*:*:*:*:*:* cpe:2.3:a:rockwellautomation:aadvance_controller:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:pacis_gtw_firmware:6.3:*:*:*:*:windows:*:* cpe:2.3:h:schneider-electric:saitel_dr:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : 4.3
v3 : 6.5 |
References | (CONFIRM) https://www.cisa.gov/uscert/ics/advisories/icsa-20-280-01 - Third Party Advisory, US Government Resource | |
References | (CONFIRM) https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-04 - Vendor Advisory | |
References | (CONFIRM) https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1131699 - Permissions Required | |
References | (CONFIRM) https://www.xylem.com/siteassets/about-xylem/cybersecurity/advisories/xylem-multismart-rockwell-isagraf.pdf - Third Party Advisory |
18 Mar 2022, 19:12
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-03-18 18:15
Updated : 2024-11-21 05:17
NVD link : CVE-2020-25180
Mitre link : CVE-2020-25180
CVE.ORG link : CVE-2020-25180
JSON object : View
Products Affected
xylem
- multismart_firmware
schneider-electric
- easergy_t300_firmware
- pacis_gtw
- pacis_gtw_firmware
- micom_c264_firmware
- saitel_dr
- scd2200_firmware
- mc-31
- epas_gtw_firmware
- saitel_dr_firmware
- easergy_t300
- easergy_c5
- easergy_c5_firmware
- epas_gtw
- saitel_dp
- cp-3
- saitel_dp_firmware
- micom_c264
rockwellautomation
- micro810_firmware
- micro820
- micro830
- micro870
- isagraf_runtime
- micro830_firmware
- micro850
- aadvance_controller
- micro820_firmware
- micro870_firmware
- isagraf_free_runtime
- micro850_firmware
- micro810