CVE-2020-25178: Rockwell Automation ISaGRAF5 Runtime Cleartext Transmission of Sensitive Information
ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Data is transferred over this protocol unencrypted, which could allow a remote unauthenticated attacker to upload, read, and delete files.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25178?
CVE-2020-25178 has a medium severity rating due to the implications of unencrypted communication.
How do I fix CVE-2020-25178?
To mitigate CVE-2020-25178, it is recommended to implement encryption for the TCP/IP communication used by ISaGRAF Workbench.
Which products are affected by CVE-2020-25178?
CVE-2020-25178 affects Schneider Electric Easergy T300 and C5 Firmware as well as various Rockwell Automation ISaGRAF Runtime versions.
What is the impact of CVE-2020-25178?
The impact of CVE-2020-25178 is that sensitive data could be exposed during transmission due to unencrypted communications.
Is there a workaround for CVE-2020-25178?
A potential workaround for CVE-2020-25178 is to restrict network access to the affected systems to reduce exposure.