CVE-2020-12069
HIGH
7,8
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
Description
AI Translation Available
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0008
Percentile
0,2th
Updated
EPSS Score Trend (Last 91 Days)
916
Use of Password Hash With Insufficient Computational Effort
IncompleteCommon Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism
Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
Operating System
762-5203\/8000-001 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-5203\/8000-001_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
V3 Simulation Runtime by Codesys
Version Range Affected
To
3.5.16.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:codesys:v3_simulation_runtime:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
750-8100 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:750-8100_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-4304\/8000-002 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-4304\/8000-002_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Control Rte V3 by Codesys
Version Range Affected
To
3.5.16.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:codesys:control_rte_v3:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-5306\/8000-002 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-5306\/8000-002_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Pmc by Pilz
Version Range Affected
From
3.0.0
(inclusive)
To
3.5.17
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:pilz:pmc:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Control For Pfc200 by Codesys
Version Range Affected
To
3.5.16.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:codesys:control_for_pfc200:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
750-8214 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:750-8214_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Control For Beaglebone by Codesys
Version Range Affected
To
3.5.16.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:codesys:control_for_beaglebone:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
750-8206 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:750-8206_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-4203\/8000-001 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-4203\/8000-001_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-6304\/8000-002 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-6304\/8000-002_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-6201\/8000-001 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-6201\/8000-001_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Controller Cecc-S Firmware by Festo
CPE Identifier
View Detailed Analysis
cpe:2.3:o:festo:controller_cecc-s_firmware:2.3.8.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Control For Iot2000 by Codesys
Version Range Affected
To
3.5.16.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:codesys:control_for_iot2000:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Control Win V3 by Codesys
Version Range Affected
To
3.5.16.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:codesys:control_win_v3:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Controller Cecc-Lk Firmware by Festo
CPE Identifier
View Detailed Analysis
cpe:2.3:o:festo:controller_cecc-lk_firmware:2.3.8.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
750-8210 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:750-8210_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-4303\/8000-002 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-4303\/8000-002_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Controller Cecc-D Firmware by Festo
CPE Identifier
View Detailed Analysis
cpe:2.3:o:festo:controller_cecc-d_firmware:2.3.8.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
750-8207 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:750-8207_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-5305\/8000-002 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-5305\/8000-002_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Hmi V3 by Codesys
Version Range Affected
To
3.5.16.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:codesys:hmi_v3:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-4305\/8000-002 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-4305\/8000-002_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Controller Cecc-D Firmware by Festo
CPE Identifier
View Detailed Analysis
cpe:2.3:o:festo:controller_cecc-d_firmware:2.3.8.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-4202\/8000-001 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-4202\/8000-001_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-4206\/8000-002 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-4206\/8000-002_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
750-8216 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:750-8216_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
750-8213 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:750-8213_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-4204\/8000-001 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-4204\/8000-001_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-6301\/8000-002 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-6301\/8000-002_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-5206\/8000-001 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-5206\/8000-001_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-5304\/8000-002 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-5304\/8000-002_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Control For Plcnext by Codesys
Version Range Affected
To
3.5.16.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:codesys:control_for_plcnext:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-4205\/8000-001 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-4205\/8000-001_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-6302\/8000-002 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-6302\/8000-002_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-5303\/8000-002 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-5303\/8000-002_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-4306\/8000-002 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-4306\/8000-002_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-6204\/8000-001 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-6204\/8000-001_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-5205\/8000-001 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-5205\/8000-001_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
750-8204 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:750-8204_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-6203\/8000-001 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-6203\/8000-001_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Control For Linux by Codesys
Version Range Affected
To
3.5.16.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:codesys:control_for_linux:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-4201\/8000-001 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-4201\/8000-001_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Controller Cecc-Lk Firmware by Festo
CPE Identifier
View Detailed Analysis
cpe:2.3:o:festo:controller_cecc-lk_firmware:2.3.8.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-5204\/8000-001 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-5204\/8000-001_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Control V3 Runtime System Toolkit by Codesys
Version Range Affected
To
3.5.16.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:codesys:control_v3_runtime_system_toolkit:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Controller Cecc-S Firmware by Festo
CPE Identifier
View Detailed Analysis
cpe:2.3:o:festo:controller_cecc-s_firmware:2.3.8.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Control For Pfc100 by Codesys
Version Range Affected
To
3.5.16.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:codesys:control_for_pfc100:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
750-8202 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:750-8202_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-4302\/8000-002 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-4302\/8000-002_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
750-8101 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:750-8101_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Control For Raspberry Pi by Codesys
Version Range Affected
To
3.5.16.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:codesys:control_for_raspberry_pi:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
750-8102 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:750-8102_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
750-8211 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:750-8211_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-4301\/8000-002 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-4301\/8000-002_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-6303\/8000-002 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-6303\/8000-002_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Control For Empc-A\/Imx6 by Codesys
Version Range Affected
To
3.5.16.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:codesys:control_for_empc-a\/imx6:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
750-8215 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:750-8215_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
750-8212 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:750-8212_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-4205\/8000-002 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-4205\/8000-002_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
752-8303\/8000-0002 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:752-8303\/8000-0002_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
750-8203 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:750-8203_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-4206\/8000-001 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-4206\/8000-001_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
750-8217 Firmware by Wago
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:750-8217_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
762-6202\/8000-001 Firmware by Wago
Version Range Affected
To
03.06.19\(18\)
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:wago:762-6202\/8000-001_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://cert.vde.com/en/advisories/VDE-2021-061/
https://cert.vde.com/en/advisories/VDE-2022-022/
https://cert.vde.com/en/advisories/VDE-2022-031/
https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=12943&token=d097958a…
https://cert.vde.com/en/advisories/VDE-2021-061/
https://cert.vde.com/en/advisories/VDE-2022-022/
https://cert.vde.com/en/advisories/VDE-2022-031/
https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=12943&token=d097958a…