7.5

CVE-2020-10624

ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes a session token on the network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Honeywell ≫ Controledge Plc Firmware Version r130.2
   Honeywell ≫ Controledge Plc Version -
Honeywell ≫ Controledge Plc Firmware Version r140
   Honeywell ≫ Controledge Plc Version -
Honeywell ≫ Controledge Plc Firmware Version r150
   Honeywell ≫ Controledge Plc Version -
Honeywell ≫ Controledge Plc Firmware Version r151
   Honeywell ≫ Controledge Plc Version -
Honeywell ≫ Controledge Rtu Firmware Version r101
   Honeywell ≫ Controledge Rtu Version -
Honeywell ≫ Controledge Rtu Firmware Version r110
   Honeywell ≫ Controledge Rtu Version -
Honeywell ≫ Controledge Rtu Firmware Version r140
   Honeywell ≫ Controledge Rtu Version -
Honeywell ≫ Controledge Rtu Firmware Version r150
   Honeywell ≫ Controledge Rtu Version -
Honeywell ≫ Controledge Rtu Firmware Version r151
   Honeywell ≫ Controledge Rtu Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.74% 0.498
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-319 Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

https://www.us-cert.gov/ics/advisories/icsa-20-175-02
Third Party Advisory
US Government Resource