CVE-2020-16231 describes a weak cryptography vulnerability in Bachmann Electronic M-Base Controllers (MSYS v1.06.14 and later), affecting numerous active and end-of-life hardware controllers. This flaw allows unauthenticated remote attackers to access password hashes if the default Security Level 0 is active, or authenticated remote attackers (or those with physical access) to decrypt passwords at Security Level 4. With a CVSS score of 8.8 (HIGH), the vulnerability presents a significant risk of high confidentiality, integrity, and availability impact due to its network attack vector and low attack complexity. There is currently no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) or significant community discussion or media coverage has been identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.06.14CPE matchmatch criteria | cpe:2.3:o:bachmann:mx207_firmware:*:*:*:*:*:*:*:* | ||
>= 1.06.14CPE matchmatch criteria | cpe:2.3:o:bachmann:mx213_firmware:*:*:*:*:*:*:*:* | ||
>= 1.06.14CPE matchmatch criteria | cpe:2.3:o:bachmann:mx220_firmware:*:*:*:*:*:*:*:* | ||
>= 1.06.14CPE matchmatch criteria | cpe:2.3:o:bachmann:mc206_firmware:*:*:*:*:*:*:*:* | ||
>= 1.06.14CPE matchmatch criteria | cpe:2.3:o:bachmann:mc212_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.