Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2020-25178 Details
Description
ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Data is transferred over this protocol unencrypted, which could allow a remote unauthenticated attacker to upload, read, and delete files.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 16, 2025Exploitation: NoneAutomatable: NoTechnical Impact: Total
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-04 | CVE | Vendor Advisory |
| https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1131699 | CVE | Permissions Required |
| https://www.cisa.gov/uscert/ics/advisories/icsa-20-280-01 | CVE | Third Party AdvisoryUS Government Resource |
| https://www.xylem.com/siteassets/about-xylem/cybersecurity/advisories/xylem-multismart-rockwell-isagraf.pdf | CVE | Vendor Advisory |
| https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-04 | [email protected] | Vendor Advisory |
| https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1131699 | [email protected] | Permissions Required |
| https://www.cisa.gov/uscert/ics/advisories/icsa-20-280-01 | [email protected] | Third Party AdvisoryUS Government Resource |
| https://www.xylem.com/siteassets/about-xylem/cybersecurity/advisories/xylem-multismart-rockwell-isagraf.pdf | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | [email protected] |
| CWE-319 | Cleartext Transmission of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| schneider-electric easergy t300 firmware | <= 2.7.1 |
CPE
Remediation
| |
| schneider-electric easergy t300 | All versions |
CPE
Remediation
| |
| schneider-electric easergy c5 firmware | < 1.1.0 |
CPE
Remediation
| |
| schneider-electric easergy c5 | All versions |
CPE
Remediation
| |
| schneider-electric micom c264 firmware | < d6.1 |
CPE
Remediation
| |
| schneider-electric micom c264 | All versions |
CPE
Remediation
| |
| schneider-electric pacis gtw firmware | 5.1 5.2 6.1 6.3 |
CPE
Remediation
| |
| schneider-electric pacis gtw | All versions |
CPE
Remediation
| |
| schneider-electric saitel dp firmware | <= 11.06.21 |
CPE
Remediation
| |
| schneider-electric saitel dp | All versions |
CPE
Remediation
| |
| schneider-electric epas gtw firmware | 6.4 |
CPE
Remediation
| |
| schneider-electric epas gtw | All versions |
CPE
Remediation
| |
| schneider-electric saitel dr firmware | <= 11.06.12 |
CPE
Remediation
| |
| schneider-electric saitel dr | All versions |
CPE
Remediation
| |
| schneider-electric scd2200 firmware | <= 10024 |
CPE
Remediation
| |
| schneider-electric cp-3 | All versions |
CPE
Remediation
| |
| schneider-electric mc-31 | All versions |
CPE
Remediation
| |
| rockwellautomation aadvance controller | <= 1.40 |
CPE
Remediation
| |
| rockwellautomation isagraf free runtime | <= 6.6.8 |
CPE
Remediation
| |
| rockwellautomation isagraf runtime | >= 5.0, < 6.0 |
CPE
Remediation
| |
| rockwellautomation micro810 firmware | All versions |
CPE
Remediation
| |
| rockwellautomation micro810 | All versions |
CPE
Remediation
| |
| rockwellautomation micro820 firmware | All versions |
CPE
Remediation
| |
| rockwellautomation micro820 | All versions |
CPE
Remediation
| |
| rockwellautomation micro830 firmware | All versions |
CPE
Remediation
| |
| rockwellautomation micro830 | All versions |
CPE
Remediation
| |
| rockwellautomation micro850 firmware | All versions |
CPE
Remediation
| |
| rockwellautomation micro850 | All versions |
CPE
Remediation
| |
| rockwellautomation micro870 firmware | All versions |
CPE
Remediation
| |
| rockwellautomation micro870 | All versions |
CPE
Remediation
| |
| xylem multismart firmware | < 3.2.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Apr 4, 2022 | Initial Analysis | [email protected] |