CVE-2020-14516
10.0
CRITICAL · CVSS 3.1 · EPSS 4.2% (pctl 91)
In your normal cycle
Critical by CVSS (10), but no sign of active exploitation.
Description
In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user password from being hashed properly.
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 4.24% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-916 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-03-18 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| rockwellautomation | factorytalk services platform |
References
→ the Explorer · watch your stack · NVD