HIGH · 7.2

CVE-2020-16231

The affected Bachmann Electronic M-Base Controllers of version MSYS v1.06.14 and later use weak cryptography to protect device passwords. Affected controllers that are actively supported include MX207...

Vulnerability Description

The affected Bachmann Electronic M-Base Controllers of version MSYS v1.06.14 and later use weak cryptography to protect device passwords. Affected controllers that are actively supported include MX207, MX213, MX220, MC206, MC212, MC220, and MH230 hardware controllers, and affected end-of-life controller include MC205, MC210, MH212, ME203, CS200, MP213, MP226, MPC240, MPC265, MPC270, MPC293, MPE270, and CPC210 hardware controllers. Security Level 0 is set at default from the manufacturer, which could allow an unauthenticated remote attacker to gain access to the password hashes. Security Level 4 is susceptible if an authenticated remote attacker or an unauthenticated person with physical access to the device reads and decrypts the password to conduct further attacks.

CVSS Score

7.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
BachmannMx207 Firmware>= 1.06.14
BachmannMx207-
BachmannMx213 Firmware>= 1.06.14
BachmannMx213-
BachmannMx220 Firmware>= 1.06.14
BachmannMx220-
BachmannMc206 Firmware>= 1.06.14
BachmannMc206-
BachmannMc212 Firmware>= 1.06.14
BachmannMc212-
BachmannMc220 Firmware>= 1.06.14
BachmannMc220-
BachmannMh230 Firmware>= 1.06.14
BachmannMh230-
BachmannMc205 Firmware>= 1.06.14
BachmannMc205-
BachmannMc210 Firmware>= 1.06.14
BachmannMc210-
BachmannMh212 Firmware>= 1.06.14
BachmannMh212-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-16231?

CVE-2020-16231 is a vulnerability with a CVSS score of 7.2 (HIGH). The affected Bachmann Electronic M-Base Controllers of version MSYS v1.06.14 and later use weak cryptography to protect device passwords. Affected controllers that are actively supported include MX207...

How severe is CVE-2020-16231?

CVE-2020-16231 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-16231?

Check the references section above for vendor advisories and patch information. Affected products include: Bachmann Mx207 Firmware, Bachmann Mx207, Bachmann Mx213 Firmware, Bachmann Mx213, Bachmann Mx220 Firmware.