CVE-2020-25182: Rockwellautomation Aadvance Controller
Medium severity, CVSS 6.7. EPSS: 0.4% chance of exploitation in the next 30 days.
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries could allow a local, unauthenticated attacker to execute arbitrary code. This vulnerability only affects ISaGRAF Runtime when running on Microsoft Windows systems.
Affected products
- Rockwellautomation Aadvance Controller: up to and including 1.40
- Rockwellautomation Isagraf Free Runtime: up to and including 6.6.8
- Rockwellautomation Isagraf Runtime: from 5.0, before 6.0 (fixed in 6.0)
- Rockwellautomation MICRO810 Firmware: affected versions not specified
- Rockwellautomation MICRO820 Firmware: affected versions not specified
- Rockwellautomation MICRO830 Firmware: affected versions not specified
- Rockwellautomation MICRO850 Firmware: affected versions not specified
- Rockwellautomation MICRO870 Firmware: affected versions not specified
- Schneider Electric Easergy c5 Firmware: before 1.1.0 (fixed in 1.1.0)
- Schneider Electric Easergy t300 Firmware: up to and including 2.7.1
- Schneider Electric Epas Gtw Firmware: version 6.4 only
- Schneider Electric Micom c264 Firmware: before d6.1 (fixed in d6.1)
- Schneider Electric Pacis Gtw Firmware: version 5.1 only; version 5.2 only; version 6.1 only; version 6.3 only
- Schneider Electric Saitel Dp Firmware: up to and including 11.06.21
- Schneider Electric Saitel Dr Firmware: up to and including 11.06.12
- Schneider Electric SCD2200 Firmware: up to and including 10024
- Xylem Multismart Firmware: before 3.2.0 (fixed in 3.2.0)
Published 2022-03-18. Last modified 2026-06-17.