Use of Password Hash With Insufficient Computational Effort in Bachmann electronic GmbH products - CVE-2020-16231

 

Use of Password Hash With Insufficient Computational Effort in Bachmann electronic GmbH products - CVE-2020-16231

Published: July 2, 2021


Vulnerability identifier: #VU54513
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-16231
CWE-ID: CWE-916
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise the target system.

The vulnerability exists due to the affected M-Base Controllers use weak cryptography to protect device passwords. A remote administrator can gain access to the password hashes.


Affected software

MX213
CPC210
MPE270
MPC293
MPC270
MPC265
MPC240
MP226
MP213
CS200
ME203
MH212
MC210
MC205
MH230
MC220
MC212
MC206
MX220
MX207
M-Base Operating System

How to mitigate CVE-2020-16231

Install updates from vendor's website.

M-Base Operating System - update to 4.49-P1

External References

Related Security Bulletins