cbcvebase.
CVE-2020-12069
published 2022-12-26

CVE-2020-12069: In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.

Affected

67 ranges· showing 25
VendorProductVersion rangeFixed in
codesyscodesys_v3_containing_the_cmpusermgr>= V3 < V3.5.16.0V3.5.16.0
codesyscontrol_for_beaglebone< 3.5.16.03.5.16.0
codesyscontrol_for_empc-a_imx6< 3.5.16.03.5.16.0
codesyscontrol_for_iot2000< 3.5.16.03.5.16.0
codesyscontrol_for_linux< 3.5.16.03.5.16.0
codesyscontrol_for_pfc100< 3.5.16.03.5.16.0
codesyscontrol_for_pfc200< 3.5.16.03.5.16.0
codesyscontrol_for_plcnext< 3.5.16.03.5.16.0
codesyscontrol_for_raspberry_pi< 3.5.16.03.5.16.0
codesyscontrol_rte_v3< 3.5.16.03.5.16.0
codesyscontrol_v3_runtime_system_toolkit< 3.5.16.03.5.16.0
codesyscontrol_win_v3< 3.5.16.03.5.16.0
codesyshmi_v3< 3.5.16.03.5.16.0
codesysv3_simulation_runtime< 3.5.16.03.5.16.0
festocontroller_cecc-d_firmware
festocontroller_cecc-d_firmware
festocontroller_cecc-lk_firmware
festocontroller_cecc-lk_firmware
festocontroller_cecc-s_firmware
festocontroller_cecc-s_firmware
pilzpmc>= 3.0.0 < 3.5.173.5.17
wago750-8100_firmware< 03.06.19\(18\)03.06.19\(18\)
wago750-8101_firmware< 03.06.19\(18\)03.06.19\(18\)
wago750-8102_firmware< 03.06.19\(18\)03.06.19\(18\)
wago750-8202_firmware< 03.06.19\(18\)03.06.19\(18\)