Use of Password Hash With Insufficient Computational Effort in Bachmann electronic GmbH products - CVE-2020-16231
Published: July 2, 2021
Vulnerability identifier: #VU54513
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-16231
CWE-ID: CWE-916
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to compromise the target system.
The vulnerability exists due to the affected M-Base Controllers use weak cryptography to protect device passwords. A remote administrator can gain access to the password hashes.
Affected software
MX213
CPC210
MPE270
MPC293
MPC270
MPC265
MPC240
MP226
MP213
CS200
ME203
MH212
MC210
MC205
MH230
MC220
MC212
MC206
MX220
MX207
M-Base Operating System
CPC210
MPE270
MPC293
MPC270
MPC265
MPC240
MP226
MP213
CS200
ME203
MH212
MC210
MC205
MH230
MC220
MC212
MC206
MX220
MX207
M-Base Operating System
How to mitigate CVE-2020-16231
Install updates from vendor's website.
M-Base Operating System - update to 4.49-P1