Learn about CVE-2020-25184 affecting Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x. Discover the impact, vulnerability details, affected systems, and mitigation steps.
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x have a vulnerability that allows local, unauthenticated attackers to access user passwords due to plaintext storage. This CVE has a CVSS base score of 7.8.
Understanding CVE-2020-25184
Rockwell Automation ISaGRAF5 Runtime Unprotected Storage of Credentials
What is CVE-2020-25184?
This CVE pertains to the storage of passwords in plaintext in a file within the same directory as the executable file, allowing attackers to compromise user passwords.
The Impact of CVE-2020-25184
Technical Details of CVE-2020-25184
Vulnerability Description
The vulnerability in ISaGRAF Runtime Versions 4.x and 5.x allows attackers to access user passwords stored in plaintext, leading to potential information disclosure.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability enables local, unauthenticated attackers to compromise user passwords by accessing the plaintext file containing the passwords.
Mitigation and Prevention
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates