CVE-2020-10605 describes an unauthenticated access vulnerability in Grundfos CIM 500 devices prior to v06.16.00, allowing attackers to retrieve password storage files. This high-severity vulnerability (CVSS 7.5) has a low attack complexity and requires no user interaction, potentially leading to full confidentiality compromise. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the potential for unauthorized access to sensitive credentials remains a significant concern. Organizations using affected Grundfos CIM 500 devices should prioritize patching to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 06.16.00CPE matchmatch criteria | cpe:2.3:o:grundfos:cim_500_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.