CVE-2020-25184: Rockwellautomation Aadvance Controller

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable without any additional modification. A local, unauthenticated attacker could compromise the user passwords, resulting in information disclosure.

Affected products

Published 2022-03-18. Last modified 2026-06-17.