CVE-2020-25180: Rockwell Automation ISaGRAF5 Runtime Use of Hard-coded Cryptographic Key
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of encryption performed with a fixed key value using the tiny encryption algorithm (TEA) on an entered or saved password. A remote, unauthenticated attacker could pass their own encrypted password to the ISaGRAF 5 Runtime, which may result in information disclosure on the device.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25180?
CVE-2020-25180 is rated as high severity due to its potential impact on the security of the affected systems.
How do I fix CVE-2020-25180?
To mitigate CVE-2020-25180, it is recommended to upgrade to the latest firmware versions provided by Schneider Electric and Rockwell Automation.
Which systems are affected by CVE-2020-25180?
CVE-2020-25180 affects Rockwell Automation ISaGRAF Runtime versions 4.x and 5.x, along with various Schneider Electric firmware versions.
What is the impact of CVE-2020-25180 on affected systems?
The impact of CVE-2020-25180 includes unauthorized execution of privileged commands due to a weak password encryption mechanism.
Is there a workaround for CVE-2020-25180?
Currently, the best workaround for CVE-2020-25180 is to apply the available software updates and avoid the use of weak passwords.