IM
IronMonkey Threat Research

CVE-2020-25176 CRITICAL

Published: 2022-03-18 | Last Modified: 2024-11-21 | Status: Modified

Description

Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not checked for reserved characters, it is possible for a remote, unauthenticated attacker to traverse an application’s directory, which could lead to remote code execution.

Additional Descriptions (1)

Algunos comandos usados por el protocolo de Rockwell Automation ISaGRAF Runtime Versiones 4.x y 5.x eXchange Layer (IXL) llevan a cabo varias operaciones de archivo en el sistema de archivos. Dado que el parámetro que apunta al nombre del archivo no es comprobado en busca de caracteres reservados, es posible que un atacante remoto no autenticado recorra el directorio de una aplicación, lo que podría conllevar a una ejecución remota de código

CVSS Metrics

Base Score: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 5.9

Base Score: 9.3 (HIGH)

AV:N/AC:M/Au:N/C:C/I:C/A:C

Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactCOMPLETE
Integrity ImpactCOMPLETE
Availability ImpactCOMPLETE

Source: [email protected]

Type: Primary

Exploitability Score: 8.6

Impact Score: 10.0

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-23
[email protected] Primary
en CWE-22

Affected Products

Vendor Product Version Update Type
schneider-electric easergy_t300_firmware * <built-in method update of dict object at 0x7e6110a56bc0> Operating System
schneider-electric easergy_c5_firmware * <built-in method update of dict object at 0x7e60e8815340> Operating System
schneider-electric micom_c264_firmware * <built-in method update of dict object at 0x7e61342e5f40> Operating System
schneider-electric pacis_gtw_firmware 5.1 <built-in method update of dict object at 0x7e61342e7c40> Operating System
schneider-electric pacis_gtw_firmware 5.2 <built-in method update of dict object at 0x7e6110a54c80> Operating System
schneider-electric pacis_gtw_firmware 6.1 <built-in method update of dict object at 0x7e61342e4600> Operating System
schneider-electric pacis_gtw_firmware 6.3 <built-in method update of dict object at 0x7e6110a549c0> Operating System
schneider-electric pacis_gtw_firmware 6.3 <built-in method update of dict object at 0x7e6110a56cc0> Operating System
schneider-electric saitel_dp_firmware * <built-in method update of dict object at 0x7e60e8817d80> Operating System
schneider-electric epas_gtw_firmware 6.4 <built-in method update of dict object at 0x7e6110a55740> Operating System
schneider-electric epas_gtw_firmware 6.4 <built-in method update of dict object at 0x7e6110a57f00> Operating System
schneider-electric saitel_dr_firmware * <built-in method update of dict object at 0x7e60bae0d640> Operating System
schneider-electric scd2200_firmware * <built-in method update of dict object at 0x7e61342e78c0> Operating System
rockwellautomation aadvance_controller * <built-in method update of dict object at 0x7e60bae49f80> Application
rockwellautomation isagraf_free_runtime * <built-in method update of dict object at 0x7e6110a56540> Application
rockwellautomation isagraf_runtime * <built-in method update of dict object at 0x7e60e8814100> Application
rockwellautomation micro810_firmware - <built-in method update of dict object at 0x7e6110a54a80> Operating System
rockwellautomation micro820_firmware - <built-in method update of dict object at 0x7e61342e7d00> Operating System
rockwellautomation micro830_firmware - <built-in method update of dict object at 0x7e61342e79c0> Operating System
rockwellautomation micro850_firmware - <built-in method update of dict object at 0x7e61342e5800> Operating System
rockwellautomation micro870_firmware - <built-in method update of dict object at 0x7e61342e6040> Operating System
xylem multismart_firmware * <built-in method update of dict object at 0x7e60e8817600> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:easergy_t300_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:easergy_t300:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:easergy_c5_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:easergy_c5:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:micom_c264_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:micom_c264:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:pacis_gtw_firmware:5.1:*:*:*:*:windows:*:*
Yes cpe:2.3:o:schneider-electric:pacis_gtw_firmware:5.2:*:*:*:*:windows:*:*
Yes cpe:2.3:o:schneider-electric:pacis_gtw_firmware:6.1:*:*:*:*:windows:*:*
Yes cpe:2.3:o:schneider-electric:pacis_gtw_firmware:6.3:*:*:*:*:linux:*:*
Yes cpe:2.3:o:schneider-electric:pacis_gtw_firmware:6.3:*:*:*:*:windows:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:pacis_gtw:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:saitel_dp_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:saitel_dp:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:epas_gtw_firmware:6.4:*:*:*:*:linux:*:*
Yes cpe:2.3:o:schneider-electric:epas_gtw_firmware:6.4:*:*:*:*:windows:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:epas_gtw:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:saitel_dr_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:saitel_dr:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:scd2200_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:cp-3:-:*:*:*:*:*:*:*
No cpe:2.3:h:schneider-electric:mc-31:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:rockwellautomation:aadvance_controller:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:rockwellautomation:isagraf_free_runtime:*:*:*:*:*:isagraf6_workbench:*:*
Yes cpe:2.3:a:rockwellautomation:isagraf_runtime:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:rockwellautomation:micro810_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:rockwellautomation:micro810:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:rockwellautomation:micro820_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:rockwellautomation:micro820:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:rockwellautomation:micro830_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:rockwellautomation:micro830:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:rockwellautomation:micro850_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:rockwellautomation:micro850:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:rockwellautomation:micro870_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:rockwellautomation:micro870:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:xylem:multismart_firmware:*:*:*:*:*:*:*:*
Notification
Message here