7.8

CVE-2020-12069

CODESYS V3 prone to Inadequate Password Hashing

In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PilzPmc Version >= 3.0.0 < 3.5.17
CodesysControl For Beaglebone Version < 3.5.16.0
CodesysControl For Iot2000 Version < 3.5.16.0
CodesysControl For Linux Version < 3.5.16.0
CodesysControl For Pfc100 Version < 3.5.16.0
CodesysControl For Pfc200 Version < 3.5.16.0
CodesysControl For Plcnext Version < 3.5.16.0
CodesysControl For Raspberry Pi Version < 3.5.16.0
CodesysControl Rte V3 Version < 3.5.16.0
CodesysControl Win V3 Version < 3.5.16.0
CodesysHmi V3 Version < 3.5.16.0
CodesysV3 Simulation Runtime Version < 3.5.16.0
FestoController Cecc-d Firmware Version2.3.8.0
   FestoController Cecc-d Version-
FestoController Cecc-d Firmware Version2.3.8.1
   FestoController Cecc-d Version-
FestoController Cecc-lk Firmware Version2.3.8.0
   FestoController Cecc-lk Version-
FestoController Cecc-lk Firmware Version2.3.8.1
   FestoController Cecc-lk Version-
FestoController Cecc-s Firmware Version2.3.8.0
   FestoController Cecc-s Version-
FestoController Cecc-s Firmware Version2.3.8.1
   FestoController Cecc-s Version-
Wago750-8217 Firmware Version-
   Wago750-8217 Version-
Wago750-8216 Firmware Version < 03.06.19\(18\)
   Wago750-8216 Version-
Wago750-8215 Firmware Version < 03.06.19\(18\)
   Wago750-8215 Version-
Wago750-8214 Firmware Version < 03.06.19\(18\)
   Wago750-8214 Version-
Wago750-8213 Firmware Version < 03.06.19\(18\)
   Wago750-8213 Version-
Wago750-8212 Firmware Version < 03.06.19\(18\)
   Wago750-8212 Version-
Wago750-8211 Firmware Version < 03.06.19\(18\)
   Wago750-8211 Version-
Wago750-8210 Firmware Version < 03.06.19\(18\)
   Wago750-8210 Version-
Wago750-8207 Firmware Version < 03.06.19\(18\)
   Wago750-8207 Version-
Wago750-8206 Firmware Version < 03.06.19\(18\)
   Wago750-8206 Version-
Wago750-8204 Firmware Version < 03.06.19\(18\)
   Wago750-8204 Version-
Wago750-8203 Firmware Version < 03.06.19\(18\)
   Wago750-8203 Version-
Wago750-8202 Firmware Version < 03.06.19\(18\)
   Wago750-8202 Version-
Wago750-8102 Firmware Version < 03.06.19\(18\)
   Wago750-8102 Version-
Wago750-8101 Firmware Version < 03.06.19\(18\)
   Wago750-8101 Version-
Wago750-8100 Firmware Version < 03.06.19\(18\)
   Wago750-8100 Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.188
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
info@cert.vde.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-916 Use of Password Hash With Insufficient Computational Effort

The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.