CVE-2020-25182: Rockwell Automation ISaGRAF5 Runtime Uncontrolled Search Path Element
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries could allow a local, unauthenticated attacker to execute arbitrary code. This vulnerability only affects ISaGRAF Runtime when running on Microsoft Windows systems.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25182?
CVE-2020-25182 has a medium severity rating due to its potential for local, unauthenticated code execution.
How do I fix CVE-2020-25182?
To address CVE-2020-25182, update to a patched version of the affected Rockwell Automation ISaGRAF Runtime software.
Which versions are affected by CVE-2020-25182?
CVE-2020-25182 affects Rockwell Automation ISaGRAF Runtime versions 5.0 to 6.0 and other specified firmware versions.
What type of vulnerability is CVE-2020-25182?
CVE-2020-25182 is classified as an uncontrolled loading of dynamic libraries vulnerability.
Who is primarily affected by CVE-2020-25182?
Organizations using vulnerable versions of Rockwell Automation ISaGRAF Runtime software are primarily at risk from CVE-2020-25182.