CVE-2020-25176: Rockwellautomation Aadvance Controller
Critical severity, CVSS 9.8. EPSS: 6.4% chance of exploitation in the next 30 days.
Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not checked for reserved characters, it is possible for a remote, unauthenticated attacker to traverse an application’s directory, which could lead to remote code execution.
Affected products
- Rockwellautomation Aadvance Controller: up to and including 1.40
- Rockwellautomation Isagraf Free Runtime: up to and including 6.6.8
- Rockwellautomation Isagraf Runtime: from 5.0, before 6.0 (fixed in 6.0)
- Rockwellautomation MICRO810 Firmware: affected versions not specified
- Rockwellautomation MICRO820 Firmware: affected versions not specified
- Rockwellautomation MICRO830 Firmware: affected versions not specified
- Rockwellautomation MICRO850 Firmware: affected versions not specified
- Rockwellautomation MICRO870 Firmware: affected versions not specified
- Schneider Electric Easergy c5 Firmware: before 1.1.0 (fixed in 1.1.0)
- Schneider Electric Easergy t300 Firmware: up to and including 2.7.1
- Schneider Electric Epas Gtw Firmware: version 6.4 only
- Schneider Electric Micom c264 Firmware: before d6.1 (fixed in d6.1)
- Schneider Electric Pacis Gtw Firmware: version 5.1 only; version 5.2 only; version 6.1 only; version 6.3 only
- Schneider Electric Saitel Dp Firmware: up to and including 11.06.21
- Schneider Electric Saitel Dr Firmware: up to and including 11.06.12
- Schneider Electric SCD2200 Firmware: up to and including 10024
- Xylem Multismart Firmware: before 3.2.0 (fixed in 3.2.0)
Published 2022-03-18. Last modified 2026-06-17.