Description
The affected Bachmann Electronic M-Base Controllers of version MSYS v1.06.14 and later use weak cryptography to protect device passwords. Affected controllers that are actively supported include MX207, MX213, MX220, MC206, MC212, MC220, and MH230 hardware controllers, and affected end-of-life controller include MC205, MC210, MH212, ME203, CS200, MP213, MP226, MPC240, MPC265, MPC270, MPC293, MPE270, and CPC210 hardware controllers. Security Level 0 is set at default from the manufacturer, which could allow an unauthenticated remote attacker to gain access to the password hashes. Security Level 4 is susceptible if an authenticated remote attacker or an unauthenticated person with physical access to the device reads and decrypts the password to conduct further attacks.
CVSS breakdown
Affected products
- Bachmann Electronic, GmbH / M1 Hardware Controller CPC210MSYS v1.06.14 – All*
- Bachmann Electronic, GmbH / M1 Hardware Controller CS200MSYS v1.06.14 – All*
- Bachmann Electronic, GmbH / M1 Hardware Controller MC205MSYS v1.06.14 – All*
- Bachmann Electronic, GmbH / M1 Hardware Controller MC206MSYS v1.06.14 – All*
- Bachmann Electronic, GmbH / M1 Hardware Controller MC210MSYS v1.06.14 – All*
- Bachmann Electronic, GmbH / M1 Hardware Controller MC212MSYS v1.06.14 – All*
- Bachmann Electronic, GmbH / M1 Hardware Controller MC220MSYS v1.06.14 – All*
- Bachmann Electronic, GmbH / M1 Hardware Controller ME203MSYS v1.06.14 – All*
- Bachmann Electronic, GmbH / M1 Hardware Controller MH212MSYS v1.06.14 – All*
- Bachmann Electronic, GmbH / M1 Hardware Controller MH230MSYS v1.06.14 – All*
- Bachmann Electronic, GmbH / M1 Hardware Controller MP213MSYS v1.06.14 – All*
- Bachmann Electronic, GmbH / M1 Hardware Controller MP226MSYS v1.06.14 – All*
- Bachmann Electronic, GmbH / M1 Hardware Controller MPC240MSYS v1.06.14 – All*
- Bachmann Electronic, GmbH / M1 Hardware Controller MPC265MSYS v1.06.14 – All*
- Bachmann Electronic, GmbH / M1 Hardware Controller MPC270MSYS v1.06.14 – All*
- Bachmann Electronic, GmbH / M1 Hardware Controller MPC293MSYS v1.06.14 – All*
- Bachmann Electronic, GmbH / M1 Hardware Controller MPE270MSYS v1.06.14 – All*
- Bachmann Electronic, GmbH / M1 Hardware Controller MX207MSYS v1.06.14 – All*
- Bachmann Electronic, GmbH / M1 Hardware Controller MX213MSYS v1.06.14 – All*
- Bachmann Electronic, GmbH / M1 Hardware Controller MX220MSYS v1.06.14 – All*
References
- VENDOR_ADVISORYhttps://www.cisa.gov/uscert/ics/advisories/icsa-21-026-02