PT-2021-8027 · Mitsubishi · Melsec Iq-R Series Safety Cpu Modules R08/16/32/120Sfcpu+1

CVE-2021-20597

·

Published

2021-08-05

·

Updated

2024-05-24

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions prior to 26 Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions prior to 11
Description The issue is related to insufficient protection of credentials, allowing a remote unauthenticated attacker to login to the target unauthorizedly by sniffing network traffic and obtaining credentials when registering user information in the target or changing a password.
Recommendations For Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions prior to 26, update the firmware to a version later than 26 to resolve the issue. For Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions prior to 11, update the firmware to a version later than 11 to resolve the issue. As a temporary workaround, consider restricting access to the network to minimize the risk of exploitation by sniffing network traffic.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03607
CVE-2021-20597

Affected Products

Melsec Iq-R Series Sil2 Process Cpu Modules R08/16/32/120Psfcpu
Melsec Iq-R Series Safety Cpu Modules R08/16/32/120Sfcpu