In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-12-26T00:00:00

Updated: 2024-08-04T11:48:58.230Z

Reserved: 2020-04-22T00:00:00

Link: CVE-2020-12069

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-12-26T19:15:10.520

Modified: 2023-11-07T03:15:19.430

Link: CVE-2020-12069

cve-icon Redhat

No data.