7.8

CVE-2020-12069

In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PilzPmc Version >= 3.0.0 < 3.5.17
CodesysControl For Beaglebone Version < 3.5.16.0
CodesysControl For Iot2000 Version < 3.5.16.0
CodesysControl For Linux Version < 3.5.16.0
CodesysControl For Pfc100 Version < 3.5.16.0
CodesysControl For Pfc200 Version < 3.5.16.0
CodesysControl For Plcnext Version < 3.5.16.0
CodesysControl For Raspberry Pi Version < 3.5.16.0
CodesysControl Rte V3 Version < 3.5.16.0
CodesysControl Win V3 Version < 3.5.16.0
CodesysHmi V3 Version < 3.5.16.0
CodesysV3 Simulation Runtime Version < 3.5.16.0
FestoController Cecc-d Firmware Version2.3.8.0
   FestoController Cecc-d Version-
FestoController Cecc-d Firmware Version2.3.8.1
   FestoController Cecc-d Version-
FestoController Cecc-lk Firmware Version2.3.8.0
   FestoController Cecc-lk Version-
FestoController Cecc-lk Firmware Version2.3.8.1
   FestoController Cecc-lk Version-
FestoController Cecc-s Firmware Version2.3.8.0
   FestoController Cecc-s Version-
FestoController Cecc-s Firmware Version2.3.8.1
   FestoController Cecc-s Version-
Wago750-8217 Firmware Version-
   Wago750-8217 Version-
Wago750-8216 Firmware Version < 03.06.19\(18\)
   Wago750-8216 Version-
Wago750-8215 Firmware Version < 03.06.19\(18\)
   Wago750-8215 Version-
Wago750-8214 Firmware Version < 03.06.19\(18\)
   Wago750-8214 Version-
Wago750-8213 Firmware Version < 03.06.19\(18\)
   Wago750-8213 Version-
Wago750-8212 Firmware Version < 03.06.19\(18\)
   Wago750-8212 Version-
Wago750-8211 Firmware Version < 03.06.19\(18\)
   Wago750-8211 Version-
Wago750-8210 Firmware Version < 03.06.19\(18\)
   Wago750-8210 Version-
Wago750-8207 Firmware Version < 03.06.19\(18\)
   Wago750-8207 Version-
Wago750-8206 Firmware Version < 03.06.19\(18\)
   Wago750-8206 Version-
Wago750-8204 Firmware Version < 03.06.19\(18\)
   Wago750-8204 Version-
Wago750-8203 Firmware Version < 03.06.19\(18\)
   Wago750-8203 Version-
Wago750-8202 Firmware Version < 03.06.19\(18\)
   Wago750-8202 Version-
Wago750-8102 Firmware Version < 03.06.19\(18\)
   Wago750-8102 Version-
Wago750-8101 Firmware Version < 03.06.19\(18\)
   Wago750-8101 Version-
Wago750-8100 Firmware Version < 03.06.19\(18\)
   Wago750-8100 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.079
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
info@cert.vde.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-916 Use of Password Hash With Insufficient Computational Effort

The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.