Insecure DLL loading in Rockwell Automation products - CVE-2020-25182
Published: June 9, 2021 / Updated: July 13, 2021
Vulnerability identifier: #VU53977
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-25182
CWE-ID: CWE-427
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to the application loads DLL libraries in an insecure manner. A local administrator can execute arbitrary code on the target system.
Affected software
AADvance Controller
ISaGRAF Free Runtime in ISaGRAF6 Workbench
ISaGRAF Runtime
Micro800
ISaGRAF Free Runtime in ISaGRAF6 Workbench
ISaGRAF Runtime
Micro800
How to mitigate CVE-2020-25182
Install update from vendor's website.
ISaGRAF Runtime - update to 5.72.00