High severity7.8NVD Advisory· Published Dec 26, 2022· Updated Jun 17, 2026
CVE-2020-12069
CVE-2020-12069
Description
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
69- cpe:2.3:a:codesys:control_for_beaglebone:*:*:*:*:*:*:*:*Range: <3.5.16.0
- cpe:2.3:a:codesys:control_for_empc-a\/imx6:*:*:*:*:*:*:*:*Range: <3.5.16.0
- cpe:2.3:a:codesys:control_for_raspberry_pi:*:*:*:*:*:*:*:*Range: <3.5.16.0
- cpe:2.3:a:codesys:control_v3_runtime_system_toolkit:*:*:*:*:*:*:*:*Range: <3.5.16.0
- cpe:2.3:a:codesys:v3_simulation_runtime:*:*:*:*:*:*:*:*Range: <3.5.16.0
cpe:2.3:o:festo:controller_cecc-d_firmware:2.3.8.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:festo:controller_cecc-d_firmware:2.3.8.0:*:*:*:*:*:*:*
- cpe:2.3:o:festo:controller_cecc-d_firmware:2.3.8.1:*:*:*:*:*:*:*
cpe:2.3:o:festo:controller_cecc-lk_firmware:2.3.8.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:festo:controller_cecc-lk_firmware:2.3.8.0:*:*:*:*:*:*:*
- cpe:2.3:o:festo:controller_cecc-lk_firmware:2.3.8.1:*:*:*:*:*:*:*
cpe:2.3:o:festo:controller_cecc-s_firmware:2.3.8.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:festo:controller_cecc-s_firmware:2.3.8.0:*:*:*:*:*:*:*
- cpe:2.3:o:festo:controller_cecc-s_firmware:2.3.8.1:*:*:*:*:*:*:*
- cpe:2.3:o:wago:750-8217_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:wago:752-8303\/8000-0002_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-4201\/8000-001_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-4202\/8000-001_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-4203\/8000-001_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-4204\/8000-001_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-4205\/8000-001_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-4205\/8000-002_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-4206\/8000-001_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-4206\/8000-002_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-4301\/8000-002_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-4302\/8000-002_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-4303\/8000-002_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-4304\/8000-002_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-4305\/8000-002_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-4306\/8000-002_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-5203\/8000-001_firmware:*:*:*:*:*:*:*:*Range: <=03.06.19\(18\)
- cpe:2.3:o:wago:762-5204\/8000-001_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-5205\/8000-001_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-5206\/8000-001_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-5303\/8000-002_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-5304\/8000-002_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-5305\/8000-002_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-5306\/8000-002_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-6201\/8000-001_firmware:*:*:*:*:*:*:*:*Range: <=03.06.19\(18\)
- cpe:2.3:o:wago:762-6202\/8000-001_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-6203\/8000-001_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-6204\/8000-001_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-6301\/8000-002_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-6302\/8000-002_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-6303\/8000-002_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- cpe:2.3:o:wago:762-6304\/8000-002_firmware:*:*:*:*:*:*:*:*Range: <03.06.19\(18\)
- Range: V3
Patches
Vulnerability mechanics
References
4- cert.vde.com/en/advisories/VDE-2021-061/nvdThird Party Advisory
- cert.vde.com/en/advisories/VDE-2022-022/nvdThird Party Advisory
- cert.vde.com/en/advisories/VDE-2022-031/nvdThird Party Advisory
- customers.codesys.com/index.phpnvdVendor Advisory
News mentions
0No linked articles in our index yet.