CVE-2020-7567
Summary
| CVE | CVE-2020-7567 |
|---|---|
| State | PUBLISHED |
| Assigner | schneider |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-19 22:15:15 UTC |
| Updated | 2026-05-29 16:16:21 UTC |
| Description | A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to find the password hash when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller and broke the encryption keys. |
Risk And Classification
Primary CVSS: v3.1 5.7 MEDIUM from [email protected]
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS: 0.000220000 probability, percentile 0.062930000 (date 2026-06-02)
Problem Types: CWE-311 | CWE-311 CWE-311: Missing Encryption of Sensitive Data
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 5.7 | MEDIUM | CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
| 3.1 | ADP | DECLARED | 7.1 | HIGH | CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 7.1 | HIGH | CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 2.9 | AV:A/AC:M/Au:N/C:P/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
AdjacentAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS v2.0 Breakdown
Access Vector
AdjacentAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:A/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Schneider-electric | Modicon M221 | - | All | All | All |
| Operating System | Schneider-electric | Modicon M221 Firmware | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | Modicon M221 All References All Versions | affected Modicon M221, all references, all versions | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Schneider Electric Modicon M221 Programmable Logic Controller | CISA | af854a3a-2127-422b-91ae-364da2661108 | us-cert.cisa.gov | Third Party Advisory, US Government Resource |
| Security Notification - Modicon M221 Programmable Logic Controller | Schneider Electric | af854a3a-2127-422b-91ae-364da2661108 | www.se.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590471 Schneider Electric Modicon M221 Programmable Logic Controller Multiple Vulnerabilities (ICSA-20-343-04)