CVE Vulnerabilities

CVE-2020-7566

Small Space of Random Values

Published: Nov 19, 2020 | Modified: Feb 03, 2022
CVSS 3.x
7.3
HIGH
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:A/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

A CWE-334: Small Space of Random Values vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break the encryption keys when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller.

Weakness

The number of possible random values is smaller than needed by the product, making it more susceptible to brute force attacks.

Affected Software

Name Vendor Start Version End Version
Modicon_m221_firmware Schneider-electric - (including) - (including)

Potential Mitigations

References