CVE-2020-25191: High severity ni compactrio vulnerability
Incorrect permissions are set by default for an API entry-point of a specific service, allowing a non-authenticated user to trigger a function that could reboot the CompactRIO (Driver versions prior to 20.5) remotely.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-25191?
CVE-2020-25191 is a vulnerability where incorrect permissions are set by default for an API entry-point of a specific service, allowing a non-authenticated user to remotely reboot the CompactRIO (Driver versions prior to 20.5).
How severe is CVE-2020-25191?
CVE-2020-25191 has a severity score of 7.5 (high).
Which software versions are affected by CVE-2020-25191?
CompactRIO Firmware versions prior to 20.5 are affected by CVE-2020-25191.
How can I fix CVE-2020-25191?
To fix CVE-2020-25191, update the CompactRIO firmware to version 20.5 or later.
Where can I find more information about CVE-2020-25191?
You can find more information about CVE-2020-25191 at the following link: [US-CERT Advisory ICSA-20-338-01](https://us-cert.cisa.gov/ics/advisories/icsa-20-338-01).