High severity7.8NVD Advisory· Published Mar 18, 2022· Updated Jun 17, 2026
CVE-2020-25184
CVE-2020-25184
Description
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable without any additional modification. A local, unauthenticated attacker could compromise the user passwords, resulting in information disclosure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
24- cpe:2.3:a:rockwellautomation:aadvance_controller:*:*:*:*:*:*:*:*Range: <=1.40
- cpe:2.3:a:rockwellautomation:isagraf_free_runtime:*:*:*:*:*:isagraf6_workbench:*:*Range: <=6.6.8
cpe:2.3:a:rockwellautomation:isagraf_runtime:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:rockwellautomation:isagraf_runtime:*:*:*:*:*:*:*:*range: >=5.0,<6.0
- (no CPE)range: 4.x, 5.x
- (no CPE)range: 4.x
- cpe:2.3:o:rockwellautomation:micro810_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:rockwellautomation:micro820_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:rockwellautomation:micro830_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:rockwellautomation:micro850_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:rockwellautomation:micro870_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:easergy_c5_firmware:*:*:*:*:*:*:*:*Range: <1.1.0
- cpe:2.3:o:schneider-electric:easergy_t300_firmware:*:*:*:*:*:*:*:*Range: <=2.7.1
cpe:2.3:o:schneider-electric:epas_gtw_firmware:6.4:*:*:*:*:linux:*:*+ 1 more
- cpe:2.3:o:schneider-electric:epas_gtw_firmware:6.4:*:*:*:*:linux:*:*
- cpe:2.3:o:schneider-electric:epas_gtw_firmware:6.4:*:*:*:*:windows:*:*
- cpe:2.3:o:schneider-electric:micom_c264_firmware:*:*:*:*:*:*:*:*Range: <d6.1
cpe:2.3:o:schneider-electric:pacis_gtw_firmware:5.1:*:*:*:*:windows:*:*+ 4 more
- cpe:2.3:o:schneider-electric:pacis_gtw_firmware:5.1:*:*:*:*:windows:*:*
- cpe:2.3:o:schneider-electric:pacis_gtw_firmware:5.2:*:*:*:*:windows:*:*
- cpe:2.3:o:schneider-electric:pacis_gtw_firmware:6.1:*:*:*:*:windows:*:*
- cpe:2.3:o:schneider-electric:pacis_gtw_firmware:6.3:*:*:*:*:linux:*:*
- cpe:2.3:o:schneider-electric:pacis_gtw_firmware:6.3:*:*:*:*:windows:*:*
- cpe:2.3:o:schneider-electric:saitel_dp_firmware:*:*:*:*:*:*:*:*Range: <=11.06.21
- cpe:2.3:o:schneider-electric:saitel_dr_firmware:*:*:*:*:*:*:*:*Range: <=11.06.12
- cpe:2.3:o:schneider-electric:scd2200_firmware:*:*:*:*:*:*:*:*Range: <=10024
Patches
Vulnerability mechanics
References
4- download.schneider-electric.com/filesnvdVendor Advisory
- www.cisa.gov/uscert/ics/advisories/icsa-20-280-01nvdThird Party AdvisoryUS Government Resource
- www.xylem.com/siteassets/about-xylem/cybersecurity/advisories/xylem-multismart-rockwell-isagraf.pdfnvdVendor Advisory
- rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1131699nvdPermissions Required
News mentions
0No linked articles in our index yet.