CVE-2020-25180
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of encryption performed with a fixed key value using the tiny encryption algorithm (TEA) on an entered or saved password. A remote, unauthenticated attacker could pass their own encrypted password to the ISaGRAF 5 Runtime, which may result in information disclosure on the device.
Published:Mar 18, 2022
Last Modified:Apr 16, 2025
EPS:Mar 18, 2022
EPSS Score:0.00135
CVSS Score:5.3
Affected Products
Vendor
Product
Action
Vendor
Rockwellautomation
Product
Aadvance Controller
Rockwellautomation
Aadvance Controller
Vendor
Rockwellautomation
Product
Isagraf Free Runtime
Rockwellautomation
Isagraf Free Runtime
Vendor
Rockwellautomation
Product
Isagraf Runtime
Rockwellautomation
Isagraf Runtime
Vendor
Rockwellautomation
Product
Micro810
Rockwellautomation
Micro810
Vendor
Rockwellautomation
Product
Micro810 Firmware
Rockwellautomation
Micro810 Firmware
Vendor
Rockwellautomation
Product
Micro820
Rockwellautomation
Micro820
Vendor
Rockwellautomation
Product
Micro820 Firmware
Rockwellautomation
Micro820 Firmware
Vendor
Rockwellautomation
Product
Micro830
Rockwellautomation
Micro830
Vendor
Rockwellautomation
Product
Micro830 Firmware
Rockwellautomation
Micro830 Firmware
Vendor
Rockwellautomation
Product
Micro850
Rockwellautomation
Micro850
Vendor
Rockwellautomation
Product
Micro850 Firmware
Rockwellautomation
Micro850 Firmware
Vendor
Rockwellautomation
Product
Micro870
Rockwellautomation
Micro870
Vendor
Rockwellautomation
Product
Micro870 Firmware
Rockwellautomation
Micro870 Firmware
Vendor
Schneider-electric
Product
Cp-3
Schneider-electric
Cp-3
Vendor
Schneider-electric
Product
Easergy C5
Schneider-electric
Easergy C5
Vendor
Schneider-electric
Product
Easergy C5 Firmware
Schneider-electric
Easergy C5 Firmware
Vendor
Schneider-electric
Product
Easergy T300
Schneider-electric
Easergy T300
Vendor
Schneider-electric
Product
Easergy T300 Firmware
Schneider-electric
Easergy T300 Firmware
Vendor
Schneider-electric
Product
Epas Gtw
Schneider-electric
Epas Gtw
Vendor
Schneider-electric
Product
Epas Gtw Firmware
Schneider-electric
Epas Gtw Firmware
Vendor
Schneider-electric
Product
Mc-31
Schneider-electric
Mc-31
Vendor
Schneider-electric
Product
Micom C264
Schneider-electric
Micom C264
Vendor
Schneider-electric
Product
Micom C264 Firmware
Schneider-electric
Micom C264 Firmware
Vendor
Schneider-electric
Product
Pacis Gtw
Schneider-electric
Pacis Gtw
Vendor
Schneider-electric
Product
Pacis Gtw Firmware
Schneider-electric
Pacis Gtw Firmware
Vendor
Schneider-electric
Product
Saitel Dp
Schneider-electric
Saitel Dp
Vendor
Schneider-electric
Product
Saitel Dp Firmware
Schneider-electric
Saitel Dp Firmware
Vendor
Schneider-electric
Product
Saitel Dr
Schneider-electric
Saitel Dr
Vendor
Schneider-electric
Product
Saitel Dr Firmware
Schneider-electric
Saitel Dr Firmware
Vendor
Schneider-electric
Product
Scd2200 Firmware
Schneider-electric
Scd2200 Firmware
Vendor
Xylem
Product
Multismart Firmware
Xylem
Multismart Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
