PT-2021-7838 · Rockwell Automation · Isagraf Runtime

Published

2021-06-08

·

Updated

2022-04-04

·

CVE-2020-25178

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ISaGRAF Workbench versions 4.x through 5.x
Description The issue is related to the communication protocol used by ISaGRAF Workbench to interact with Rockwell Automation ISaGRAF Runtime. This protocol, which operates over TCP/IP, allows for various file system operations, including the uploading of applications. However, data transferred via this protocol is unencrypted, potentially enabling a remote, unauthenticated attacker to upload, read, and delete files.
Recommendations For versions 4.x through 5.x, consider implementing encryption for data transferred over the TCP/IP protocol to prevent unauthorized access. As a temporary workaround, restrict access to the TCP/IP communication protocol to minimize the risk of exploitation.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03539
CVE-2020-25178

Affected Products

Isagraf Runtime