CVE-2020-12069

In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CERTVDECNA
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
VendorProductVersion
pilzpmc
3.0.0 ≤
𝑥
< 3.5.17
codesyscontrol_for_beaglebone
𝑥
< 3.5.16.0
codesyscontrol_for_empc-a\/imx6
𝑥
< 3.5.16.0
codesyscontrol_for_iot2000
𝑥
< 3.5.16.0
codesyscontrol_for_linux
𝑥
< 3.5.16.0
codesyscontrol_for_pfc100
𝑥
< 3.5.16.0
codesyscontrol_for_pfc200
𝑥
< 3.5.16.0
codesyscontrol_for_plcnext
𝑥
< 3.5.16.0
codesyscontrol_for_raspberry_pi
𝑥
< 3.5.16.0
codesyscontrol_rte_v3
𝑥
< 3.5.16.0
codesyscontrol_v3_runtime_system_toolkit
𝑥
< 3.5.16.0
codesyscontrol_win_v3
𝑥
< 3.5.16.0
codesyshmi_v3
𝑥
< 3.5.16.0
codesysv3_simulation_runtime
𝑥
< 3.5.16.0
festocontroller_cecc-d_firmware
2.3.8.0
festocontroller_cecc-d_firmware
2.3.8.1
festocontroller_cecc-lk_firmware
2.3.8.0
festocontroller_cecc-lk_firmware
2.3.8.1
festocontroller_cecc-s_firmware
2.3.8.0
festocontroller_cecc-s_firmware
2.3.8.1
wago750-8217_firmware
-
wago750-8216_firmware
𝑥
< 03.06.19\(18\)
wago750-8215_firmware
𝑥
< 03.06.19\(18\)
wago750-8214_firmware
𝑥
< 03.06.19\(18\)
wago750-8213_firmware
𝑥
< 03.06.19\(18\)
wago750-8212_firmware
𝑥
< 03.06.19\(18\)
wago750-8211_firmware
𝑥
< 03.06.19\(18\)
wago750-8210_firmware
𝑥
< 03.06.19\(18\)
wago750-8207_firmware
𝑥
< 03.06.19\(18\)
wago750-8206_firmware
𝑥
< 03.06.19\(18\)
wago750-8204_firmware
𝑥
< 03.06.19\(18\)
wago750-8203_firmware
𝑥
< 03.06.19\(18\)
wago750-8202_firmware
𝑥
< 03.06.19\(18\)
wago750-8102_firmware
𝑥
< 03.06.19\(18\)
wago750-8101_firmware
𝑥
< 03.06.19\(18\)
wago750-8100_firmware
𝑥
< 03.06.19\(18\)
wago762-4201\/8000-001_firmware
𝑥
< 03.06.19\(18\)
wago762-4202\/8000-001_firmware
𝑥
< 03.06.19\(18\)
wago762-4203\/8000-001_firmware
𝑥
< 03.06.19\(18\)
wago762-4204\/8000-001_firmware
𝑥
< 03.06.19\(18\)
wago762-4205\/8000-001_firmware
𝑥
< 03.06.19\(18\)
wago762-4205\/8000-002_firmware
𝑥
< 03.06.19\(18\)
wago762-4206\/8000-001_firmware
𝑥
< 03.06.19\(18\)
wago762-4206\/8000-002_firmware
𝑥
< 03.06.19\(18\)
wago762-4301\/8000-002_firmware
𝑥
< 03.06.19\(18\)
wago762-4302\/8000-002_firmware
𝑥
< 03.06.19\(18\)
wago762-4303\/8000-002_firmware
𝑥
< 03.06.19\(18\)
wago762-4304\/8000-002_firmware
𝑥
< 03.06.19\(18\)
wago762-4305\/8000-002_firmware
𝑥
< 03.06.19\(18\)
wago762-4306\/8000-002_firmware
𝑥
< 03.06.19\(18\)
wago762-5203\/8000-001_firmware
𝑥
≤ 03.06.19\(18\)
wago762-5204\/8000-001_firmware
𝑥
< 03.06.19\(18\)
wago762-5205\/8000-001_firmware
𝑥
< 03.06.19\(18\)
wago762-5206\/8000-001_firmware
𝑥
< 03.06.19\(18\)
wago762-5303\/8000-002_firmware
𝑥
< 03.06.19\(18\)
wago762-5304\/8000-002_firmware
𝑥
< 03.06.19\(18\)
wago762-5305\/8000-002_firmware
𝑥
< 03.06.19\(18\)
wago762-5306\/8000-002_firmware
𝑥
< 03.06.19\(18\)
wago762-6201\/8000-001_firmware
𝑥
≤ 03.06.19\(18\)
wago762-6202\/8000-001_firmware
𝑥
< 03.06.19\(18\)
wago762-6203\/8000-001_firmware
𝑥
< 03.06.19\(18\)
wago762-6204\/8000-001_firmware
𝑥
< 03.06.19\(18\)
wago762-6301\/8000-002_firmware
𝑥
< 03.06.19\(18\)
wago762-6302\/8000-002_firmware
𝑥
< 03.06.19\(18\)
wago762-6303\/8000-002_firmware
𝑥
< 03.06.19\(18\)
wago762-6304\/8000-002_firmware
𝑥
< 03.06.19\(18\)
wago752-8303\/8000-0002_firmware
𝑥
< 03.06.19\(18\)
𝑥
= Vulnerable software versions