CVE-2020-16231
Published on: Not Yet Published
Last Modified on: 06/08/2022 02:47:00 PM UTC
Certain versions of Cpc210 from Bachmann contain the following vulnerability:
The affected Bachmann Electronic M-Base Controllers of version MSYS v1.06.14 and later use weak cryptography to protect device passwords. Affected controllers that are actively supported include MX207, MX213, MX220, MC206, MC212, MC220, and MH230 hardware controllers, and affected end-of-life controller include MC205, MC210, MH212, ME203, CS200, MP213, MP226, MPC240, MPC265, MPC270, MPC293, MPE270, and CPC210 hardware controllers. Security Level 0 is set at default from the manufacturer, which could allow an unauthenticated remote attacker to gain access to the password hashes. Security Level 4 is susceptible if an authenticated remote attacker or an unauthenticated person with physical access to the device reads and decrypts the password to conduct further attacks.
- CVE-2020-16231 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 6.5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
All Bachmann M1 System Processor Modules | CISA | www.cisa.gov text/html |
![]() |
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Bachmann | Cpc210 | - | All | All | All |
Operating System | Bachmann | Cpc210 Firmware | All | All | All | All |
Hardware
| Bachmann | Cs200 | - | All | All | All |
Operating System | Bachmann | Cs200 Firmware | All | All | All | All |
Hardware
| Bachmann | Mc205 | - | All | All | All |
Operating System | Bachmann | Mc205 Firmware | All | All | All | All |
Hardware
| Bachmann | Mc206 | - | All | All | All |
Operating System | Bachmann | Mc206 Firmware | All | All | All | All |
Hardware
| Bachmann | Mc210 | - | All | All | All |
Operating System | Bachmann | Mc210 Firmware | All | All | All | All |
Hardware
| Bachmann | Mc212 | - | All | All | All |
Operating System | Bachmann | Mc212 Firmware | All | All | All | All |
Hardware
| Bachmann | Mc220 | - | All | All | All |
Operating System | Bachmann | Mc220 Firmware | All | All | All | All |
Hardware
| Bachmann | Me203 | - | All | All | All |
Operating System | Bachmann | Me203 Firmware | All | All | All | All |
Hardware
| Bachmann | Mh212 | - | All | All | All |
Operating System | Bachmann | Mh212 Firmware | All | All | All | All |
Hardware
| Bachmann | Mh230 | - | All | All | All |
Operating System | Bachmann | Mh230 Firmware | All | All | All | All |
Hardware
| Bachmann | Mp213 | - | All | All | All |
Operating System | Bachmann | Mp213 Firmware | All | All | All | All |
Hardware
| Bachmann | Mp226 | - | All | All | All |
Operating System | Bachmann | Mp226 Firmware | All | All | All | All |
Hardware
| Bachmann | Mpc240 | - | All | All | All |
Operating System | Bachmann | Mpc240 Firmware | All | All | All | All |
Hardware
| Bachmann | Mpc265 | - | All | All | All |
Operating System | Bachmann | Mpc265 Firmware | All | All | All | All |
Hardware
| Bachmann | Mpc270 | - | All | All | All |
Operating System | Bachmann | Mpc270 Firmware | All | All | All | All |
Hardware
| Bachmann | Mpc293 | - | All | All | All |
Operating System | Bachmann | Mpc293 Firmware | All | All | All | All |
Hardware
| Bachmann | Mpe270 | - | All | All | All |
Operating System | Bachmann | Mpe270 Firmware | All | All | All | All |
Hardware
| Bachmann | Mx207 | - | All | All | All |
Operating System | Bachmann | Mx207 Firmware | All | All | All | All |
Hardware
| Bachmann | Mx213 | - | All | All | All |
Operating System | Bachmann | Mx213 Firmware | All | All | All | All |
Hardware
| Bachmann | Mx220 | - | All | All | All |
Operating System | Bachmann | Mx220 Firmware | All | All | All | All |
- cpe:2.3:h:bachmann:cpc210:-:*:*:*:*:*:*:*:
- cpe:2.3:o:bachmann:cpc210_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:bachmann:cs200:-:*:*:*:*:*:*:*:
- cpe:2.3:o:bachmann:cs200_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:bachmann:mc205:-:*:*:*:*:*:*:*:
- cpe:2.3:o:bachmann:mc205_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:bachmann:mc206:-:*:*:*:*:*:*:*:
- cpe:2.3:o:bachmann:mc206_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:bachmann:mc210:-:*:*:*:*:*:*:*:
- cpe:2.3:o:bachmann:mc210_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:bachmann:mc212:-:*:*:*:*:*:*:*:
- cpe:2.3:o:bachmann:mc212_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:bachmann:mc220:-:*:*:*:*:*:*:*:
- cpe:2.3:o:bachmann:mc220_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:bachmann:me203:-:*:*:*:*:*:*:*:
- cpe:2.3:o:bachmann:me203_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:bachmann:mh212:-:*:*:*:*:*:*:*:
- cpe:2.3:o:bachmann:mh212_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:bachmann:mh230:-:*:*:*:*:*:*:*:
- cpe:2.3:o:bachmann:mh230_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:bachmann:mp213:-:*:*:*:*:*:*:*:
- cpe:2.3:o:bachmann:mp213_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:bachmann:mp226:-:*:*:*:*:*:*:*:
- cpe:2.3:o:bachmann:mp226_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:bachmann:mpc240:-:*:*:*:*:*:*:*:
- cpe:2.3:o:bachmann:mpc240_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:bachmann:mpc265:-:*:*:*:*:*:*:*:
- cpe:2.3:o:bachmann:mpc265_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:bachmann:mpc270:-:*:*:*:*:*:*:*:
- cpe:2.3:o:bachmann:mpc270_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:bachmann:mpc293:-:*:*:*:*:*:*:*:
- cpe:2.3:o:bachmann:mpc293_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:bachmann:mpe270:-:*:*:*:*:*:*:*:
- cpe:2.3:o:bachmann:mpe270_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:bachmann:mx207:-:*:*:*:*:*:*:*:
- cpe:2.3:o:bachmann:mx207_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:bachmann:mx213:-:*:*:*:*:*:*:*:
- cpe:2.3:o:bachmann:mx213_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:bachmann:mx220:-:*:*:*:*:*:*:*:
- cpe:2.3:o:bachmann:mx220_firmware:*:*:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2020-16231 : The affected Bachmann Electronic M-Base Controllers of version MSYS v1.06.14 and later use weak cr… twitter.com/i/web/status/1… | 2022-05-19 18:06:38 |
![]() |
New vulnerability on the NVD: CVE-2020-16231 ift.tt/2BRvlpJ May 20, 2022 at 06:15AM | 2022-05-19 20:12:00 |
![]() |
CVE-2020-16231 | 2022-05-19 19:39:00 |