CVE-2020-16231
Summary
| CVE | CVE-2020-16231 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-19 18:15:00 UTC |
| Updated | 2022-06-08 14:47:00 UTC |
| Description | The affected Bachmann Electronic M-Base Controllers of version MSYS v1.06.14 and later use weak cryptography to protect device passwords. Affected controllers that are actively supported include MX207, MX213, MX220, MC206, MC212, MC220, and MH230 hardware controllers, and affected end-of-life controller include MC205, MC210, MH212, ME203, CS200, MP213, MP226, MPC240, MPC265, MPC270, MPC293, MPE270, and CPC210 hardware controllers. Security Level 0 is set at default from the manufacturer, which could allow an unauthenticated remote attacker to gain access to the password hashes. Security Level 4 is susceptible if an authenticated remote attacker or an unauthenticated person with physical access to the device reads and decrypts the password to conduct further attacks. |
Risk And Classification
Problem Types: CWE-916
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Bachmann | Cpc210 | - | All | All | All |
| Operating System | Bachmann | Cpc210 Firmware | All | All | All | All |
| Hardware | Bachmann | Cs200 | - | All | All | All |
| Operating System | Bachmann | Cs200 Firmware | All | All | All | All |
| Hardware | Bachmann | Mc205 | - | All | All | All |
| Operating System | Bachmann | Mc205 Firmware | All | All | All | All |
| Hardware | Bachmann | Mc206 | - | All | All | All |
| Operating System | Bachmann | Mc206 Firmware | All | All | All | All |
| Hardware | Bachmann | Mc210 | - | All | All | All |
| Operating System | Bachmann | Mc210 Firmware | All | All | All | All |
| Hardware | Bachmann | Mc212 | - | All | All | All |
| Operating System | Bachmann | Mc212 Firmware | All | All | All | All |
| Hardware | Bachmann | Mc220 | - | All | All | All |
| Operating System | Bachmann | Mc220 Firmware | All | All | All | All |
| Hardware | Bachmann | Me203 | - | All | All | All |
| Operating System | Bachmann | Me203 Firmware | All | All | All | All |
| Hardware | Bachmann | Mh212 | - | All | All | All |
| Operating System | Bachmann | Mh212 Firmware | All | All | All | All |
| Hardware | Bachmann | Mh230 | - | All | All | All |
| Operating System | Bachmann | Mh230 Firmware | All | All | All | All |
| Hardware | Bachmann | Mp213 | - | All | All | All |
| Operating System | Bachmann | Mp213 Firmware | All | All | All | All |
| Hardware | Bachmann | Mp226 | - | All | All | All |
| Operating System | Bachmann | Mp226 Firmware | All | All | All | All |
| Hardware | Bachmann | Mpc240 | - | All | All | All |
| Operating System | Bachmann | Mpc240 Firmware | All | All | All | All |
| Hardware | Bachmann | Mpc265 | - | All | All | All |
| Operating System | Bachmann | Mpc265 Firmware | All | All | All | All |
| Hardware | Bachmann | Mpc270 | - | All | All | All |
| Operating System | Bachmann | Mpc270 Firmware | All | All | All | All |
| Hardware | Bachmann | Mpc293 | - | All | All | All |
| Operating System | Bachmann | Mpc293 Firmware | All | All | All | All |
| Hardware | Bachmann | Mpe270 | - | All | All | All |
| Operating System | Bachmann | Mpe270 Firmware | All | All | All | All |
| Hardware | Bachmann | Mx207 | - | All | All | All |
| Operating System | Bachmann | Mx207 Firmware | All | All | All | All |
| Hardware | Bachmann | Mx213 | - | All | All | All |
| Operating System | Bachmann | Mx213 Firmware | All | All | All | All |
| Hardware | Bachmann | Mx220 | - | All | All | All |
| Operating System | Bachmann | Mx220 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| All Bachmann M1 System Processor Modules | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.