CVE-2020-16231: Bachmann CPC210 Firmware
High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.
The affected Bachmann Electronic M-Base Controllers of version MSYS v1.06.14 and later use weak cryptography to protect device passwords. Affected controllers that are actively supported include MX207, MX213, MX220, MC206, MC212, MC220, and MH230 hardware controllers, and affected end-of-life controller include MC205, MC210, MH212, ME203, CS200, MP213, MP226, MPC240, MPC265, MPC270, MPC293, MPE270, and CPC210 hardware controllers. Security Level 0 is set at default from the manufacturer, which could allow an unauthenticated remote attacker to gain access to the password hashes. Security Level 4 is susceptible if an authenticated remote attacker or an unauthenticated person with physical access to the device reads and decrypts the password to conduct further attacks.
Affected products
- Bachmann CPC210 Firmware: from 1.06.14
- Bachmann CS200 Firmware: from 1.06.14
- Bachmann MC205 Firmware: from 1.06.14
- Bachmann MC206 Firmware: from 1.06.14
- Bachmann MC210 Firmware: from 1.06.14
- Bachmann MC212 Firmware: from 1.06.14
- Bachmann MC220 Firmware: from 1.06.14
- Bachmann ME203 Firmware: from 1.06.14
- Bachmann MH212 Firmware: from 1.06.14
- Bachmann MH230 Firmware: from 1.06.14
- Bachmann MP213 Firmware: from 1.06.14
- Bachmann MP226 Firmware: from 1.06.14
- Bachmann MPC240 Firmware: from 1.06.14
- Bachmann MPC265 Firmware: from 1.06.14
- Bachmann MPC270 Firmware: from 1.06.14
- Bachmann MPC293 Firmware: from 1.06.14
- Bachmann MPE270 Firmware: from 1.06.14
- Bachmann MX207 Firmware: from 1.06.14
- Bachmann MX213 Firmware: from 1.06.14
- Bachmann MX220 Firmware: from 1.06.14
Published 2022-05-19. Last modified 2026-06-17.