Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rq23-5rjf-c828

Опубликовано: 19 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of encryption performed with a fixed key value using the tiny encryption algorithm (TEA) on an entered or saved password. A remote, unauthenticated attacker could pass their own encrypted password to the ISaGRAF 5 Runtime, which may result in information disclosure on the device.

Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of encryption performed with a fixed key value using the tiny encryption algorithm (TEA) on an entered or saved password. A remote, unauthenticated attacker could pass their own encrypted password to the ISaGRAF 5 Runtime, which may result in information disclosure on the device.

EPSS

Процентиль: 29%
0.00103
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 5.3
nvd
почти 4 года назад

Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of encryption performed with a fixed key value using the tiny encryption algorithm (TEA) on an entered or saved password. A remote, unauthenticated attacker could pass their own encrypted password to the ISaGRAF 5 Runtime, which may result in information disclosure on the device.

CVSS3: 5.3
fstec
больше 4 лет назад

Уязвимость среды разработки приложений для программируемых логических контроллеров ISaGRAF Runtime Rockwell Automation, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 29%
0.00103
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-798