PT-2021-7832 · Microsoft+1 · Windows+1
Published
2021-06-08
·
Updated
2022-08-26
·
CVE-2020-25182
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Rockwell Automation ISaGRAF Runtime versions 4.x through 5.x
Description
The issue is related to the uncontrolled loading of dynamic libraries by Rockwell Automation ISaGRAF Runtime, which could allow a local, unauthenticated attacker to execute arbitrary code. This problem only affects ISaGRAF Runtime when running on Microsoft Windows systems.
Recommendations
For versions 4.x through 5.x, consider restricting the loading of dynamic libraries to prevent arbitrary code execution until a patch is available.
As a temporary workaround, consider disabling the dynamic library loading feature in ISaGRAF Runtime until a fix is provided.
Restrict access to the system to minimize the risk of exploitation.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Isagraf Runtime
Windows