In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.
The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.
Link | Tags |
---|---|
https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=12943&token=d097958a67ba382de688916f77e3013c0802fade&download= | vendor advisory |
https://cert.vde.com/en/advisories/VDE-2021-061/ | third party advisory vendor advisory |
https://cert.vde.com/en/advisories/VDE-2022-031/ | third party advisory vendor advisory |
https://cert.vde.com/en/advisories/VDE-2022-022/ | third party advisory vendor advisory |