8.8

CVE-2020-16231

The affected Bachmann Electronic M-Base Controllers of version MSYS v1.06.14 and later use weak cryptography to protect device passwords. Affected controllers that are actively supported include MX207, MX213, MX220, MC206, MC212, MC220, and MH230 hardware controllers, and affected end-of-life controller include MC205, MC210, MH212, ME203, CS200, MP213, MP226, MPC240, MPC265, MPC270, MPC293, MPE270, and CPC210 hardware controllers. Security Level 0 is set at default from the manufacturer, which could allow an unauthenticated remote attacker to gain access to the password hashes. Security Level 4 is susceptible if an authenticated remote attacker or an unauthenticated person with physical access to the device reads and decrypts the password to conduct further attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BachmannMx207 Firmware Version >= 1.06.14
   BachmannMx207 Version-
BachmannMx213 Firmware Version >= 1.06.14
   BachmannMx213 Version-
BachmannMx220 Firmware Version >= 1.06.14
   BachmannMx220 Version-
BachmannMc206 Firmware Version >= 1.06.14
   BachmannMc206 Version-
BachmannMc212 Firmware Version >= 1.06.14
   BachmannMc212 Version-
BachmannMc220 Firmware Version >= 1.06.14
   BachmannMc220 Version-
BachmannMh230 Firmware Version >= 1.06.14
   BachmannMh230 Version-
BachmannMc205 Firmware Version >= 1.06.14
   BachmannMc205 Version-
BachmannMc210 Firmware Version >= 1.06.14
   BachmannMc210 Version-
BachmannMh212 Firmware Version >= 1.06.14
   BachmannMh212 Version-
BachmannMe203 Firmware Version >= 1.06.14
   BachmannMe203 Version-
BachmannCs200 Firmware Version >= 1.06.14
   BachmannCs200 Version-
BachmannMp213 Firmware Version >= 1.06.14
   BachmannMp213 Version-
BachmannMp226 Firmware Version >= 1.06.14
   BachmannMp226 Version-
BachmannMpc240 Firmware Version >= 1.06.14
   BachmannMpc240 Version-
BachmannMpc265 Firmware Version >= 1.06.14
   BachmannMpc265 Version-
BachmannMpc270 Firmware Version >= 1.06.14
   BachmannMpc270 Version-
BachmannMpc293 Firmware Version >= 1.06.14
   BachmannMpc293 Version-
BachmannMpe270 Firmware Version >= 1.06.14
   BachmannMpe270 Version-
BachmannCpc210 Firmware Version >= 1.06.14
   BachmannCpc210 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.483
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
ics-cert@hq.dhs.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-916 Use of Password Hash With Insufficient Computational Effort

The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.