CVE-2020-14516
Severity CVSS v4.0:
Pending analysis
Type:
CWE-916
Use of Password Hash With Insufficient Computational Effort
Publication date:
18/03/2021
Last modified:
26/03/2021
Description
In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user password from being hashed properly.
Impact
Base Score 3.x
10.00
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:rockwellautomation:factorytalk_services_platform:6.10.00:*:*:*:*:*:*:* | ||
| cpe:2.3:a:rockwellautomation:factorytalk_services_platform:6.11.00:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



