Vulnerability Description
A CWE-760: Use of a One-Way Hash with a Predictable Salt vulnerability exists in Modicon M221 (all references, all versions), that could allow an attacker to pre-compute the hash value using dictionary attack technique such as rainbow tables, effectively disabling the protection that an unpredictable salt would provide.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Modicon M221 Firmware | All versions |
| Schneider-Electric | Modicon M221 | - |
Related Weaknesses (CWE)
References
- https://us-cert.cisa.gov/ics/advisories/icsa-20-343-04Third Party AdvisoryUS Government Resource
- https://www.se.com/ww/en/download/document/SEVD-2020-315-05/Vendor Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-20-343-04Third Party AdvisoryUS Government Resource
- https://www.se.com/ww/en/download/document/SEVD-2020-315-05/Vendor Advisory
FAQ
What is CVE-2020-28214?
CVE-2020-28214 is a vulnerability with a CVSS score of 5.5 (MEDIUM). A CWE-760: Use of a One-Way Hash with a Predictable Salt vulnerability exists in Modicon M221 (all references, all versions), that could allow an attacker to pre-compute the hash value using dictionar...
How severe is CVE-2020-28214?
CVE-2020-28214 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-28214?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Modicon M221 Firmware, Schneider-Electric Modicon M221.