First published: Mon Dec 26 2022(Updated: )
In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pilz PMC | >=3.0.0<3.5.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12067 is classified as a high severity vulnerability due to the potential impact on user account security.
To mitigate CVE-2020-12067, upgrade the Pilz PMC programming tool to version 3.5.17 or later.
CVE-2020-12067 allows an attacker to change a user's password without knowing the current password, compromising account security.
CVE-2020-12067 affects all versions of Pilz PMC prior to 3.5.17.
Using Pilz PMC programming tool versions 3.0.0 to 3.5.16 is not safe due to the risk posed by CVE-2020-12067.