CVE-2020-10624: High severity honeywell controledge plc firmware vulnerability
Published Jun 26, 2020
·Updated
ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes a session token on the network.
Affected Software
11 affected components
Honeywell Controledge Plc Firmware=r130.2
Honeywell Controledge Plc Firmware=r140
Honeywell Controledge Plc Firmware=r150
Honeywell Controledge Plc Firmware=r151
Honeywell ControlEdge PLC
Honeywell Controledge Rtu Firmware=r101
Honeywell Controledge Rtu Firmware=r110
Honeywell Controledge Rtu Firmware=r140
Honeywell Controledge Rtu Firmware=r150
Honeywell Controledge Rtu Firmware=r151
Honeywell Controledge Rtu
Event History
Jun 26, 2020
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-10624.
2
What is the severity of CVE-2020-10624?
CVE-2020-10624 has a severity rating of high with a value of 7.5.
3
Which software versions are affected by CVE-2020-10624?
ControlEdge PLC versions R130.2, R140, R150, and R151, as well as RTU versions R101, R110, R140, R150, and R151 are affected by CVE-2020-10624.
4
What is the description of CVE-2020-10624?
CVE-2020-10624 is a vulnerability in ControlEdge PLC and RTU devices that exposes a session token on the network.
5
Where can I find more information about CVE-2020-10624?
You can find more information about CVE-2020-10624 on the US-CERT website at https://www.us-cert.gov/ics/advisories/icsa-20-175-02.