CVE-2020-10624
Severity CVSS v4.0:
Pending analysis
Type:
CWE-319
Cleartext Transmission of Sensitive Information
Publication date:
26/06/2020
Last modified:
07/07/2020
Description
ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes a session token on the network.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:honeywell:controledge_plc_firmware:r130.2:*:*:*:*:*:*:* | ||
cpe:2.3:o:honeywell:controledge_plc_firmware:r140:*:*:*:*:*:*:* | ||
cpe:2.3:o:honeywell:controledge_plc_firmware:r150:*:*:*:*:*:*:* | ||
cpe:2.3:o:honeywell:controledge_plc_firmware:r151:*:*:*:*:*:*:* | ||
cpe:2.3:h:honeywell:controledge_plc:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:honeywell:controledge_rtu_firmware:r101:*:*:*:*:*:*:* | ||
cpe:2.3:o:honeywell:controledge_rtu_firmware:r110:*:*:*:*:*:*:* | ||
cpe:2.3:o:honeywell:controledge_rtu_firmware:r140:*:*:*:*:*:*:* | ||
cpe:2.3:o:honeywell:controledge_rtu_firmware:r150:*:*:*:*:*:*:* | ||
cpe:2.3:o:honeywell:controledge_rtu_firmware:r151:*:*:*:*:*:*:* | ||
cpe:2.3:h:honeywell:controledge_rtu:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page