cbcvebase.
CVE-2020-12069
published 2022-12-26

CVE-2020-12069: In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.16%
6.0th percentile
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.

Affected

67 ranges· showing 25
VendorProductVersion rangeFixed in
codesyscodesys_v3_containing_the_cmpusermgr>= V3 < V3.5.16.0V3.5.16.0
codesyscontrol_for_beaglebone< 3.5.16.03.5.16.0
codesyscontrol_for_empc-a_imx6< 3.5.16.03.5.16.0
codesyscontrol_for_iot2000< 3.5.16.03.5.16.0
codesyscontrol_for_linux< 3.5.16.03.5.16.0
codesyscontrol_for_pfc100< 3.5.16.03.5.16.0
codesyscontrol_for_pfc200< 3.5.16.03.5.16.0
codesyscontrol_for_plcnext< 3.5.16.03.5.16.0
codesyscontrol_for_raspberry_pi< 3.5.16.03.5.16.0
codesyscontrol_rte_v3< 3.5.16.03.5.16.0
codesyscontrol_v3_runtime_system_toolkit< 3.5.16.03.5.16.0
codesyscontrol_win_v3< 3.5.16.03.5.16.0
codesyshmi_v3< 3.5.16.03.5.16.0
codesysv3_simulation_runtime< 3.5.16.03.5.16.0
festocontroller_cecc-d_firmware
festocontroller_cecc-d_firmware
festocontroller_cecc-lk_firmware
festocontroller_cecc-lk_firmware
festocontroller_cecc-s_firmware
festocontroller_cecc-s_firmware
pilzpmc>= 3.0.0 < 3.5.173.5.17
wago750-8100_firmware< 03.06.19\(18\)03.06.19\(18\)
wago750-8101_firmware< 03.06.19\(18\)03.06.19\(18\)
wago750-8102_firmware< 03.06.19\(18\)03.06.19\(18\)
wago750-8202_firmware< 03.06.19\(18\)03.06.19\(18\)
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.