CVE-2020-12069: CODESYS V3 prone to Inadequate Password Hashing
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12069?
The severity of CVE-2020-12069 is classified as medium due to the weak password hashing vulnerability that can be exploited by local attackers.
How do I fix CVE-2020-12069?
To fix CVE-2020-12069, you should upgrade to CODESYS versions 3.5.17.0 or later that implement stronger password hashing algorithms.
Who is affected by CVE-2020-12069?
CVE-2020-12069 affects various CODESYS V3 products and devices utilizing the CmpUserMgr across multiple versions prior to 3.5.17.0.
What is the impact of CVE-2020-12069?
The impact of CVE-2020-12069 includes the potential for local attackers to gain full control of the affected devices due to weak password storage.
Is there a workaround for CVE-2020-12069?
There is no known effective workaround for CVE-2020-12069, and upgrading the software is the recommended action.