Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not checked for reserved characters, it is possible for a remote, unauthenticated attacker to traverse an application’s directory, which could lead to remote code execution.
Algunos comandos usados por el protocolo de Rockwell Automation ISaGRAF Runtime Versiones 4.x y 5.x eXchange Layer (IXL) llevan a cabo varias operaciones de archivo en el sistema de archivos. Dado que el parámetro que apunta al nombre del archivo no es comprobado en busca de caracteres reservados, es posible que un atacante remoto no autenticado recorra el directorio de una aplicación, lo que podría conllevar a una ejecución remota de código
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AV:N/AC:M/Au:N/C:C/I:C/A:C
| Access Vector | NETWORK |
|---|---|
| Access Complexity | MEDIUM |
| Authentication | NONE |
| Confidentiality Impact | COMPLETE |
| Integrity Impact | COMPLETE |
| Availability Impact | COMPLETE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-23
|
| [email protected] | Primary |
en
CWE-22
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| schneider-electric | easergy_t300_firmware | * | <built-in method update of dict object at 0x7e6110a56bc0> | Operating System |
| schneider-electric | easergy_c5_firmware | * | <built-in method update of dict object at 0x7e60e8815340> | Operating System |
| schneider-electric | micom_c264_firmware | * | <built-in method update of dict object at 0x7e61342e5f40> | Operating System |
| schneider-electric | pacis_gtw_firmware | 5.1 | <built-in method update of dict object at 0x7e61342e7c40> | Operating System |
| schneider-electric | pacis_gtw_firmware | 5.2 | <built-in method update of dict object at 0x7e6110a54c80> | Operating System |
| schneider-electric | pacis_gtw_firmware | 6.1 | <built-in method update of dict object at 0x7e61342e4600> | Operating System |
| schneider-electric | pacis_gtw_firmware | 6.3 | <built-in method update of dict object at 0x7e6110a549c0> | Operating System |
| schneider-electric | pacis_gtw_firmware | 6.3 | <built-in method update of dict object at 0x7e6110a56cc0> | Operating System |
| schneider-electric | saitel_dp_firmware | * | <built-in method update of dict object at 0x7e60e8817d80> | Operating System |
| schneider-electric | epas_gtw_firmware | 6.4 | <built-in method update of dict object at 0x7e6110a55740> | Operating System |
| schneider-electric | epas_gtw_firmware | 6.4 | <built-in method update of dict object at 0x7e6110a57f00> | Operating System |
| schneider-electric | saitel_dr_firmware | * | <built-in method update of dict object at 0x7e60bae0d640> | Operating System |
| schneider-electric | scd2200_firmware | * | <built-in method update of dict object at 0x7e61342e78c0> | Operating System |
| rockwellautomation | aadvance_controller | * | <built-in method update of dict object at 0x7e60bae49f80> | Application |
| rockwellautomation | isagraf_free_runtime | * | <built-in method update of dict object at 0x7e6110a56540> | Application |
| rockwellautomation | isagraf_runtime | * | <built-in method update of dict object at 0x7e60e8814100> | Application |
| rockwellautomation | micro810_firmware | - | <built-in method update of dict object at 0x7e6110a54a80> | Operating System |
| rockwellautomation | micro820_firmware | - | <built-in method update of dict object at 0x7e61342e7d00> | Operating System |
| rockwellautomation | micro830_firmware | - | <built-in method update of dict object at 0x7e61342e79c0> | Operating System |
| rockwellautomation | micro850_firmware | - | <built-in method update of dict object at 0x7e61342e5800> | Operating System |
| rockwellautomation | micro870_firmware | - | <built-in method update of dict object at 0x7e61342e6040> | Operating System |
| xylem | multismart_firmware | * | <built-in method update of dict object at 0x7e60e8817600> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:easergy_t300_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:easergy_t300:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:easergy_c5_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:easergy_c5:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:micom_c264_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:micom_c264:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:pacis_gtw_firmware:5.1:*:*:*:*:windows:*:* |
| Yes | cpe:2.3:o:schneider-electric:pacis_gtw_firmware:5.2:*:*:*:*:windows:*:* |
| Yes | cpe:2.3:o:schneider-electric:pacis_gtw_firmware:6.1:*:*:*:*:windows:*:* |
| Yes | cpe:2.3:o:schneider-electric:pacis_gtw_firmware:6.3:*:*:*:*:linux:*:* |
| Yes | cpe:2.3:o:schneider-electric:pacis_gtw_firmware:6.3:*:*:*:*:windows:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:pacis_gtw:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:saitel_dp_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:saitel_dp:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:epas_gtw_firmware:6.4:*:*:*:*:linux:*:* |
| Yes | cpe:2.3:o:schneider-electric:epas_gtw_firmware:6.4:*:*:*:*:windows:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:epas_gtw:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:saitel_dr_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:saitel_dr:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:scd2200_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:cp-3:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:schneider-electric:mc-31:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:rockwellautomation:aadvance_controller:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:rockwellautomation:isagraf_free_runtime:*:*:*:*:*:isagraf6_workbench:*:* |
| Yes | cpe:2.3:a:rockwellautomation:isagraf_runtime:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:rockwellautomation:micro810_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:rockwellautomation:micro810:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:rockwellautomation:micro820_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:rockwellautomation:micro820:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:rockwellautomation:micro830_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:rockwellautomation:micro830:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:rockwellautomation:micro850_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:rockwellautomation:micro850:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:rockwellautomation:micro870_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:rockwellautomation:micro870:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:xylem:multismart_firmware:*:*:*:*:*:*:*:* |