Rockwell Automation ISaGRAF5 Runtime Relative Path Traversal
Vulnerability Description
Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not checked for reserved characters, it is possible for a remote, unauthenticated attacker to traverse an application’s directory, which could lead to remote code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-25176
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Kaspersky reported these vulnerabilities to Rockwell Automation.
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-20-280-01
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1131699
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-04
- https://www.xylem.com/siteassets/about-xylem/cybersecurity/advisories/xylem-multismart-rockwell-isagraf.pdf
More from Rockwell Automation
View All →Affected Vendor
Rockwell Automation
View all reports →