High severity7.5NVD Advisory· Published Mar 18, 2022· Updated Jun 17, 2026
CVE-2020-25178
CVE-2020-25178
Description
ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Data is transferred over this protocol unencrypted, which could allow a remote unauthenticated attacker to upload, read, and delete files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
24- cpe:2.3:a:rockwellautomation:aadvance_controller:*:*:*:*:*:*:*:*Range: <=1.40
- cpe:2.3:a:rockwellautomation:isagraf_free_runtime:*:*:*:*:*:isagraf6_workbench:*:*Range: <=6.6.8
cpe:2.3:a:rockwellautomation:isagraf_runtime:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:rockwellautomation:isagraf_runtime:*:*:*:*:*:*:*:*range: >=5.0,<6.0
- (no CPE)range: 4.x and 5.x
- (no CPE)range: 4.x
- cpe:2.3:o:rockwellautomation:micro810_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:rockwellautomation:micro820_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:rockwellautomation:micro830_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:rockwellautomation:micro850_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:rockwellautomation:micro870_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:easergy_c5_firmware:*:*:*:*:*:*:*:*Range: <1.1.0
- cpe:2.3:o:schneider-electric:easergy_t300_firmware:*:*:*:*:*:*:*:*Range: <=2.7.1
cpe:2.3:o:schneider-electric:epas_gtw_firmware:6.4:*:*:*:*:linux:*:*+ 1 more
- cpe:2.3:o:schneider-electric:epas_gtw_firmware:6.4:*:*:*:*:linux:*:*
- cpe:2.3:o:schneider-electric:epas_gtw_firmware:6.4:*:*:*:*:windows:*:*
- cpe:2.3:o:schneider-electric:micom_c264_firmware:*:*:*:*:*:*:*:*Range: <d6.1
cpe:2.3:o:schneider-electric:pacis_gtw_firmware:5.1:*:*:*:*:windows:*:*+ 4 more
- cpe:2.3:o:schneider-electric:pacis_gtw_firmware:5.1:*:*:*:*:windows:*:*
- cpe:2.3:o:schneider-electric:pacis_gtw_firmware:5.2:*:*:*:*:windows:*:*
- cpe:2.3:o:schneider-electric:pacis_gtw_firmware:6.1:*:*:*:*:windows:*:*
- cpe:2.3:o:schneider-electric:pacis_gtw_firmware:6.3:*:*:*:*:linux:*:*
- cpe:2.3:o:schneider-electric:pacis_gtw_firmware:6.3:*:*:*:*:windows:*:*
- cpe:2.3:o:schneider-electric:saitel_dp_firmware:*:*:*:*:*:*:*:*Range: <=11.06.21
- cpe:2.3:o:schneider-electric:saitel_dr_firmware:*:*:*:*:*:*:*:*Range: <=11.06.12
- cpe:2.3:o:schneider-electric:scd2200_firmware:*:*:*:*:*:*:*:*Range: <=10024
Patches
Vulnerability mechanics
References
4- download.schneider-electric.com/filesnvdVendor Advisory
- www.cisa.gov/uscert/ics/advisories/icsa-20-280-01nvdThird Party AdvisoryUS Government Resource
- www.xylem.com/siteassets/about-xylem/cybersecurity/advisories/xylem-multismart-rockwell-isagraf.pdfnvdVendor Advisory
- rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1131699nvdPermissions Required
News mentions
0No linked articles in our index yet.