SB2021060920 - Multiple vulnerabilities in Rockwell Automation ISaGRAF5 Runtime



SB2021060920 - Multiple vulnerabilities in Rockwell Automation ISaGRAF5 Runtime

Published: June 9, 2021 Updated: July 13, 2021

Security Bulletin ID SB2021060920
Severity
Medium
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 40% Low 60%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 secuirty vulnerabilities.


1) Path traversal (CVE-ID: CVE-2020-25176)

The vulnerability allows a remote user to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences within the ISaGRAF eXchange Layer (IXL) protocol. A remote administrator can send a specially crafted HTTP request and read arbitrary files on the system.


2) Cleartext storage of sensitive information (CVE-ID: CVE-2020-25184)

The vulnerability allows a local user to gain access to other users' credentials.

The vulnerability exists due to the ISaGRAF Runtime stored credentials in plain text in a configuration file on the system. A local user can view contents of the configuration file and gain access to passwords for 3rd party integration.


3) Cleartext transmission of sensitive information (CVE-ID: CVE-2020-25178)

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to software uses insecure communication channel to transmit sensitive information. A remote attacker can upload, read, and delete files.


4) Insecure DLL loading (CVE-ID: CVE-2020-25182)

The vulnerability allows a local user to compromise vulnerable system.

The vulnerability exists due to the application loads DLL libraries in an insecure manner. A local administrator can execute arbitrary code on the target system.


5) Use of Hard-coded Cryptographic Key (CVE-ID: CVE-2020-25180)

The vulnerability allows a remote attacker to disclose sensitive information on the target system.

The vulnerability exists due to use of hard-coded cryptographic key issue. A remote attacker can pass their own encrypted password to the ISaGRAF 5 Runtime, and cause information disclosure on the device.


Remediation

Install update from vendor's website.