CVE-2020-25184: Rockwellautomation Aadvance Controller
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable without any additional modification. A local, unauthenticated attacker could compromise the user passwords, resulting in information disclosure.
Affected products
- Rockwellautomation Aadvance Controller: up to and including 1.40
- Rockwellautomation Isagraf Free Runtime: up to and including 6.6.8
- Rockwellautomation Isagraf Runtime: from 5.0, before 6.0 (fixed in 6.0)
- Rockwellautomation MICRO810 Firmware: affected versions not specified
- Rockwellautomation MICRO820 Firmware: affected versions not specified
- Rockwellautomation MICRO830 Firmware: affected versions not specified
- Rockwellautomation MICRO850 Firmware: affected versions not specified
- Rockwellautomation MICRO870 Firmware: affected versions not specified
- Schneider Electric Easergy c5 Firmware: before 1.1.0 (fixed in 1.1.0)
- Schneider Electric Easergy t300 Firmware: up to and including 2.7.1
- Schneider Electric Epas Gtw Firmware: version 6.4 only
- Schneider Electric Micom c264 Firmware: before d6.1 (fixed in d6.1)
- Schneider Electric Pacis Gtw Firmware: version 5.1 only; version 5.2 only; version 6.1 only; version 6.3 only
- Schneider Electric Saitel Dp Firmware: up to and including 11.06.21
- Schneider Electric Saitel Dr Firmware: up to and including 11.06.12
- Schneider Electric SCD2200 Firmware: up to and including 10024
- Xylem Multismart Firmware: before 3.2.0 (fixed in 3.2.0)
Published 2022-03-18. Last modified 2026-06-17.