CVE-2020-25176
Since the parameter pointing to the file name is not checked for reserved characters, it is possible for a remote, unauthenticated attacker to traverse an application’s directory, which could lead to remote code execution.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not checked for reserved characters, it is possible for a remote, unauthenticated attacker to traverse an application’s directory, which could lead to remote code execution.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 6.42% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-23, CWE-22
- Affected
- schneider-electric/easergy t300 firmware · schneider-electric/easergy c5 firmware · schneider-electric/micom c264 firmware · schneider-electric/pacis gtw firmware · schneider-electric/saitel dp firmware · schneider-electric/epas gtw firmware · schneider-electric/saitel dr firmware · schneider-electric/scd2200 firmware · rockwellautomation/aadvance controller · rockwellautomation/isagraf free runtime · rockwellautomation/isagraf runtime · rockwellautomation/micro810 firmware · rockwellautomation/micro820 firmware · rockwellautomation/micro830 firmware · rockwellautomation/micro850 firmware · rockwellautomation/micro870 firmware · xylem/multismart firmware
- Source
- ics-cert@hq.dhs.gov
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-04Mitigation, Vendor Advisory
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1131699Permissions Required
- https://www.cisa.gov/uscert/ics/advisories/icsa-20-280-01Third Party Advisory, US Government Resource
- https://www.xylem.com/siteassets/about-xylem/cybersecurity/advisories/xylem-multismart-rockwell-isagraf.pdfThird Party Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-04Mitigation, Vendor Advisory
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1131699Permissions Required
- https://www.cisa.gov/uscert/ics/advisories/icsa-20-280-01Third Party Advisory, US Government Resource
- https://www.xylem.com/siteassets/about-xylem/cybersecurity/advisories/xylem-multismart-rockwell-isagraf.pdfThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.