Unrated severityNVD Advisory· Published Dec 26, 2022· Updated Apr 14, 2025
CODESYS V3 prone to Inadequate Password Hashing
CVE-2020-12069
Description
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.
Affected products
1- Range: V3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- cert.vde.com/en/advisories/VDE-2021-061/mitrevendor-advisory
- cert.vde.com/en/advisories/VDE-2022-022/mitrevendor-advisory
- cert.vde.com/en/advisories/VDE-2022-031/mitrevendor-advisory
- customers.codesys.com/index.phpmitrevendor-advisory
News mentions
0No linked articles in our index yet.