ZeroHour

CVE-2020-16231

CVSS 3.1
8.8 high
EPSS
<1%p56
Published
()
Modified
Description

The affected Bachmann Electronic M-Base Controllers of version MSYS v1.06.14 and later use weak cryptography to protect device passwords. Affected controllers that are actively supported include MX207, MX213, MX220, MC206, MC212, MC220, and MH230 hardware controllers, and affected end-of-life controller include MC205, MC210, MH212, ME203, CS200, MP213, MP226, MPC240, MPC265, MPC270, MPC293, MPE270, and CPC210 hardware controllers. Security Level 0 is set at default from the manufacturer, which could allow an unauthenticated remote attacker to gain access to the password hashes. Security Level 4 is susceptible if an authenticated remote attacker or an unauthenticated person with physical access to the device reads and decrypts the password to conduct further attacks.

Vendors
bachmann
Products
mx207 firmware, mx213 firmware, mx220 firmware, mc206 firmware, mc212 firmware, mc220 firmware, mh230 firmware, mc205 firmware, mc210 firmware, mh212 firmware, me203 firmware, cs200 firmware
Weakness
CWE-916
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.