7.5

CVE-2020-10628

ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes unencrypted passwords on the network.

Data is provided by the National Vulnerability Database (NVD)
HoneywellControledge Plc Firmware Versionr130.2
   HoneywellControledge Plc Version-
HoneywellControledge Plc Firmware Versionr140
   HoneywellControledge Plc Version-
HoneywellControledge Plc Firmware Versionr150
   HoneywellControledge Plc Version-
HoneywellControledge Plc Firmware Versionr151
   HoneywellControledge Plc Version-
HoneywellControledge Rtu Firmware Versionr101
   HoneywellControledge Rtu Version-
HoneywellControledge Rtu Firmware Versionr110
   HoneywellControledge Rtu Version-
HoneywellControledge Rtu Firmware Versionr140
   HoneywellControledge Rtu Version-
HoneywellControledge Rtu Firmware Versionr150
   HoneywellControledge Rtu Version-
HoneywellControledge Rtu Firmware Versionr151
   HoneywellControledge Rtu Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.11% 0.269
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-319 Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.