Medium severity6.7NVD Advisory· Published Mar 18, 2022· Updated Jun 17, 2026
CVE-2020-25182
CVE-2020-25182
Description
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries could allow a local, unauthenticated attacker to execute arbitrary code. This vulnerability only affects ISaGRAF Runtime when running on Microsoft Windows systems.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
24- cpe:2.3:a:rockwellautomation:aadvance_controller:*:*:*:*:*:*:*:*Range: <=1.40
- cpe:2.3:a:rockwellautomation:isagraf_free_runtime:*:*:*:*:*:isagraf6_workbench:*:*Range: <=6.6.8
cpe:2.3:a:rockwellautomation:isagraf_runtime:*:*:*:*:*:windows:*:*+ 2 more
- cpe:2.3:a:rockwellautomation:isagraf_runtime:*:*:*:*:*:windows:*:*range: >=5.0,<6.0
- (no CPE)range: 4.x, 5.x
- (no CPE)range: 4.x
- cpe:2.3:o:rockwellautomation:micro810_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:rockwellautomation:micro820_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:rockwellautomation:micro830_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:rockwellautomation:micro850_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:rockwellautomation:micro870_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:easergy_c5_firmware:*:*:*:*:*:*:*:*Range: <1.1.0
- cpe:2.3:o:schneider-electric:easergy_t300_firmware:*:*:*:*:*:*:*:*Range: <=2.7.1
cpe:2.3:o:schneider-electric:epas_gtw_firmware:6.4:*:*:*:*:linux:*:*+ 1 more
- cpe:2.3:o:schneider-electric:epas_gtw_firmware:6.4:*:*:*:*:linux:*:*
- cpe:2.3:o:schneider-electric:epas_gtw_firmware:6.4:*:*:*:*:windows:*:*
- cpe:2.3:o:schneider-electric:micom_c264_firmware:*:*:*:*:*:*:*:*Range: <d6.1
cpe:2.3:o:schneider-electric:pacis_gtw_firmware:5.1:*:*:*:*:windows:*:*+ 4 more
- cpe:2.3:o:schneider-electric:pacis_gtw_firmware:5.1:*:*:*:*:windows:*:*
- cpe:2.3:o:schneider-electric:pacis_gtw_firmware:5.2:*:*:*:*:windows:*:*
- cpe:2.3:o:schneider-electric:pacis_gtw_firmware:6.1:*:*:*:*:windows:*:*
- cpe:2.3:o:schneider-electric:pacis_gtw_firmware:6.3:*:*:*:*:linux:*:*
- cpe:2.3:o:schneider-electric:pacis_gtw_firmware:6.3:*:*:*:*:windows:*:*
- cpe:2.3:o:schneider-electric:saitel_dp_firmware:*:*:*:*:*:*:*:*Range: <=11.06.21
- cpe:2.3:o:schneider-electric:saitel_dr_firmware:*:*:*:*:*:*:*:*Range: <=11.06.12
- cpe:2.3:o:schneider-electric:scd2200_firmware:*:*:*:*:*:*:*:*Range: <=10024
Patches
Vulnerability mechanics
References
4- download.schneider-electric.com/filesnvdVendor Advisory
- rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1131699nvdPermissions RequiredVendor Advisory
- www.cisa.gov/uscert/ics/advisories/icsa-20-280-01nvdThird Party AdvisoryUS Government Resource
- www.xylem.com/siteassets/about-xylem/cybersecurity/advisories/xylem-multismart-rockwell-isagraf.pdfnvdVendor Advisory
News mentions
0No linked articles in our index yet.