CVE-2020-16231 - CVE House
Back to Database
Status published High CVE-2020-16231

All Bachmann M1 System Processor Modules - Use of Password Hash with Insufficient Computational Effort

Vulnerability Description

The affected Bachmann Electronic M-Base Controllers of version MSYS v1.06.14 and later use weak cryptography to protect device passwords. Affected controllers that are actively supported include MX207, MX213, MX220, MC206, MC212, MC220, and MH230 hardware controllers, and affected end-of-life controller include MC205, MC210, MH212, ME203, CS200, MP213, MP226, MPC240, MPC265, MPC270, MPC293, MPE270, and CPC210 hardware controllers. Security Level 0 is set at default from the manufacturer, which could allow an unauthenticated remote attacker to gain access to the password hashes. Security Level 4 is susceptible if an authenticated remote attacker or an unauthenticated person with physical access to the device reads and decrypts the password to conduct further attacks.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-16231

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Bachmann Electronic, GmbH

View all reports →

Affected Software

M1 Hardware Controller MX207, M1 Hardware Controller MX213, M1 Hardware Controller MX220, M1 Hardware Controller MC206, M1 Hardware Controller MC212, M1 Hardware Controller MC220, M1 Hardware Controller MH230, M1 Hardware Controller MC205, M1 Hardware Controller MC210, M1 Hardware Controller MH212, M1 Hardware Controller ME203, M1 Hardware Controller CS200, M1 Hardware Controller MP213, M1 Hardware Controller MP226, M1 Hardware Controller MPC240, M1 Hardware Controller MPC265, M1 Hardware Controller MPC270, M1 Hardware Controller MPC293, M1 Hardware Controller MPE270, M1 Hardware Controller CPC210
Vulnerable Versions:
MSYS v1.06.14

Timeline

Official Publish: May 19th, 2022
Last Modified: April 16th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.