CVE-2020-7565 Vulnerability Details

  /     /     /  

CVE-2020-7565 Metadata Quick Info

CVE Published: 19/11/2020 | CVE Updated: 04/08/2024 | CVE Year: 2020
Source: schneider | Vendor: n/a | Product: Modicon M221, all references, all versions
Status : PUBLISHED

CVE-2020-7565 Description

A CWE-326: Inadequate Encryption Strength vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break the encryption key when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-326
CWE Name: CWE-326: Inadequate Encryption Strength
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).