CVE-2020-16231
All Bachmann M1 System Processor Modules - Use of Password Hash with Insufficient Computational Effort
The affected Bachmann Electronic M-Base Controllers of version MSYS v1.06.14 and later use weak cryptography to protect device passwords. Affected controllers that are actively supported include MX207, MX213, MX220, MC206, MC212, MC220, and MH230 hardware controllers, and affected end-of-life controller include MC205, MC210, MH212, ME203, CS200, MP213, MP226, MPC240, MPC265, MPC270, MPC293, MPE270, and CPC210 hardware controllers. Security Level 0 is set at default from the manufacturer, which could allow an unauthenticated remote attacker to gain access to the password hashes. Security Level 4 is susceptible if an authenticated remote attacker or an unauthenticated person with physical access to the device reads and decrypts the password to conduct further attacks.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Bachmann Electronic, GmbH · M1 Hardware Controller CPC210Bachmann Electronic, GmbH · M1 Hardware Controller CS200Bachmann Electronic, GmbH · M1 Hardware Controller MC205Bachmann Electronic, GmbH · M1 Hardware Controller MC206Bachmann Electronic, GmbH · M1 Hardware Controller MC210Bachmann Electronic, GmbH · M1 Hardware Controller MC212Bachmann Electronic, GmbH · M1 Hardware Controller MC220Bachmann Electronic, GmbH · M1 Hardware Controller ME203Bachmann Electronic, GmbH · M1 Hardware Controller MH212Bachmann Electronic, GmbH · M1 Hardware Controller MH230Bachmann Electronic, GmbH · M1 Hardware Controller MP213Bachmann Electronic, GmbH · M1 Hardware Controller MP226Bachmann Electronic, GmbH · M1 Hardware Controller MPC240Bachmann Electronic, GmbH · M1 Hardware Controller MPC265Bachmann Electronic, GmbH · M1 Hardware Controller MPC270Bachmann Electronic, GmbH · M1 Hardware Controller MPC293Bachmann Electronic, GmbH · M1 Hardware Controller MPE270Bachmann Electronic, GmbH · M1 Hardware Controller MX207Bachmann Electronic, GmbH · M1 Hardware Controller MX213Bachmann Electronic, GmbH · M1 Hardware Controller MX220Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →