CVE-2020-16231 Information

Description

The affected Bachmann Electronic M-Base Controllers of version MSYS v1.06.14 and later use weak cryptography to protect device passwords. Affected controllers that are actively supported include MX207 MX213 MX220 MC206 MC212 MC220 and MH230 hardware controllers and affected end-of-life controller include MC205 MC210 MH212 ME203 CS200 MP213 MP226 MPC240 MPC265 MPC270 MPC293 MPE270 and CPC210 hardware controllers. Security Level 0 is set at default from the manufacturer which could allow an unauthenticated remote attacker to gain access to the password hashes. Security Level 4 is susceptible if an authenticated remote attacker or an unauthenticated person with physical access to the device reads and decrypts the password to conduct further attacks.

Reference

https://www.cisa.gov/uscert/ics/advisories/icsa-21-026-02

Share on: