CVE-2020-12067

Severity CVSS v4.0:
Pending analysis
Type:
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
Publication date:
26/12/2022
Last modified:
05/01/2023

Description

In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pilz:pmc:*:*:*:*:*:*:*:* 3.0.0 (including) 3.5.17 (excluding)


References to Advisories, Solutions, and Tools