Cleartext storage of sensitive information in Rockwell Automation products - CVE-2020-25184

 

Cleartext storage of sensitive information in Rockwell Automation products - CVE-2020-25184

Published: June 9, 2021 / Updated: July 13, 2021


Vulnerability identifier: #VU53974
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-25184
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to other users' credentials.

The vulnerability exists due to the ISaGRAF Runtime stored credentials in plain text in a configuration file on the system. A local user can view contents of the configuration file and gain access to passwords for 3rd party integration.


Affected software

AADvance Controller
ISaGRAF Free Runtime in ISaGRAF6 Workbench
ISaGRAF Runtime
Micro800
ioPAC 8500-2-RJ45-IEC-T
ioPAC 8500-2-M12-IEC-T
ioPAC 8600-CPU30-M12-IEC-T
ioPAC 8600-CPU30-RJ45-IEC-T

How to mitigate CVE-2020-25184

Install update from vendor's website.

ISaGRAF Runtime - update to 5.72.00

External References

Related Security Bulletins