CVE Vulnerabilities

CVE-2020-10628

Cleartext Transmission of Sensitive Information

Published: Jun 26, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes unencrypted passwords on the network.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

NameVendorStart VersionEnd Version
Controledge_plc_firmwareHoneywellr130.2 (including)r130.2 (including)
Controledge_plc_firmwareHoneywellr140 (including)r140 (including)
Controledge_plc_firmwareHoneywellr150 (including)r150 (including)
Controledge_plc_firmwareHoneywellr151 (including)r151 (including)

Potential Mitigations

References