PT-2021-8030 · Mitsubishi · Melsec Iq-R Series Sil2 Process Cpu Modules R08/16/32/120Psfcpu+1

·

CVE-2021-20594

·

Published

2021-08-05

·

Updated

2024-05-24

CVSS v2.0

5.4

Medium

VectorAV:N/AC:H/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions MELSEC iQ-R Series Safety CPU modules R08/16/32/120SFCPU firmware versions prior to 26 MELSEC iQ-R Series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions prior to 11
Description The issue is related to the exposure of sensitive information to unauthorized actors due to a lack of protection for service data. This can allow a remote attacker to gain unauthorized access to protected information. Specifically, it enables a remote unauthenticated attacker to acquire legitimate user names registered in the module via a brute-force attack on user names.
Recommendations For MELSEC iQ-R Series Safety CPU modules R08/16/32/120SFCPU firmware versions prior to 26, update the firmware to version 26 or later. For MELSEC iQ-R Series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions prior to 11, update the firmware to version 11 or later. As a temporary workaround, consider restricting access to the modules to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03611
CVE-2021-20594

Affected Products

Melsec Iq-R Series Sil2 Process Cpu Modules R08/16/32/120Psfcpu
Melsec Iq-R Series Safety Cpu Modules R08/16/32/120Sfcpu