PT-2022-8324 · Pilz+1 · Pilz Pmc+1
Published
2022-12-26
·
Updated
2024-10-03
·
CVE-2020-12069
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CODESYS V3 products versions prior to 3.5.16.0
Pilz PMC programming tool versions 3.x prior to 3.5.17
Description
The issue is related to a weak hashing algorithm used for storing online communication passwords in the CODESYS Control runtime system. This weakness can be exploited by a local attacker with low privileges to gain full control of the device. The password-hashing feature requires insufficient computational effort, making it vulnerable to attacks.
Recommendations
For CODESYS V3 products versions prior to 3.5.16.0, update to version 3.5.16.0 or later to resolve the issue.
For Pilz PMC programming tool versions 3.x prior to 3.5.17, update to version 3.5.17 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
CmpUserMgr component to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Codesys V3
Pilz Pmc