ZeroHour

CVE-2020-12069

CVSS 3.1
7.8 high
EPSS
<1%p6
Published
()
Modified
Description

In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.

Vendors
pilzcodesysfestowago
Products
pmc, control for beaglebone, control for empc-a\/imx6, control for iot2000, control for linux, control for pfc100, control for pfc200, control for plcnext, control for raspberry pi, control rte v3, control v3 runtime system toolkit, control win v3
Weakness
CWE-916
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.