CVE-2020-28214
A CWE-760: Use of a One-Way Hash with a Predictable Salt vulnerability exists in Modicon M221 (all references, all versions), that could allow an attacker to pre-compute the hash value using dictionary attack technique such as rainbow tables, effectively disabling the protection that an unpredictable salt would provide.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.09%
- CWE
- CWE-760
- Published
- 2020-12-11
- Last modified
- 2026-05-28
Affected products
- n/a Modicon M221 (all references, all versions)
Weakness type
Related vulnerabilities
- CVE-2026-46749 — A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected...
- CVE-2026-9370 — ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecretKeySaltGenerator hash predictable salt
- CVE-2025-9290 — Authentication Weakness on Omada Controllers, Gateways and Access Points
- CVE-2024-13951 — One way hash with predictable salt
- CVE-2025-26486 — Broken or Risky Cryptographic Algorithm, Use of Password Hash...
- CVE-2023-22599
- CVE-2021-38314 — Gutenberg Template Library & Redux Framework <= 4.2.11 Sensitive Information Disclosure
- CVE-2018-5552 — DocuTrac DTISQLInstaller.exe Hard-Coded Salt