SB2021060920 - Multiple vulnerabilities in Rockwell Automation ISaGRAF5 Runtime
Published: June 9, 2021 Updated: July 13, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 secuirty vulnerabilities.
1) Path traversal (CVE-ID: CVE-2020-25176)
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences within the ISaGRAF eXchange Layer (IXL) protocol. A remote administrator can send a specially crafted HTTP request and read arbitrary files on the system.
2) Cleartext storage of sensitive information (CVE-ID: CVE-2020-25184)
The vulnerability allows a local user to gain access to other users' credentials.
The vulnerability exists due to the ISaGRAF Runtime stored credentials in plain text in a configuration file on the system. A local user can view contents of the configuration file and gain access to passwords for 3rd party integration.
3) Cleartext transmission of sensitive information (CVE-ID: CVE-2020-25178)
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to software uses insecure communication channel to transmit sensitive information. A remote attacker can upload, read, and delete files.
4) Insecure DLL loading (CVE-ID: CVE-2020-25182)
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to the application loads DLL libraries in an insecure manner. A local administrator can execute arbitrary code on the target system.
5) Use of Hard-coded Cryptographic Key (CVE-ID: CVE-2020-25180)
The vulnerability allows a remote attacker to disclose sensitive information on the target system.
The vulnerability exists due to use of hard-coded cryptographic key issue. A remote attacker can pass their own encrypted password to the ISaGRAF 5 Runtime, and cause information disclosure on the device.
Remediation
Install update from vendor's website.
References
- https://ics-cert.us-cert.gov/advisories/icsa-20-280-01
- https://ics-cert.kaspersky.com/advisories/klcert-advisories/2021/07/13/klcert-20-022-rockwell-automation-isagraf-runtime-code-execution-due-to-relative-path-traversal
- https://ics-cert.kaspersky.com/advisories/klcert-advisories/2021/07/13/klcert-20-026-rockwell-automation-isagraf-runtime-information-disclosure-due-to-cleartext-storage-of-passwords-in-a-file-and-memory
- https://ics-cert.kaspersky.com/advisories/klcert-advisories/2021/07/13/klcert-20-023-rockwell-automation-isagraf-runtime-information-disclosure-due-to-cleartext-transmission-of-information-over-ixl-protocol
- https://ics-cert.kaspersky.com/advisories/klcert-advisories/2021/07/13/klcert-20-024-rockwell-automation-isagraf-runtime-code-execution-due-to-uncontrolled-search-path-element
- https://ics-cert.kaspersky.com/advisories/klcert-advisories/2021/07/13/klcert-20-025-rockwell-automation-isagraf-runtime-information-disclosure-due-to-hard-coded-cryptographic-key