Description
Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to the target unauthorizedly by sniffing network traffic and obtaining credentials when registering user information in the target or changing a password.
Published: 2021-08-06
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-8015 Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to the target unauthorizedly by sniffing network traffic and obtaining credentials when registering user information in the target or changing a password.
History

No history.

Subscriptions

Mitsubishielectric R08psfcpu R08psfcpu Firmware R08sfcpu R08sfcpu Firmware R120psfcpu R120psfcpu Firmware R120sfcpu R120sfcpu Firmware R16psfcpu R16psfcpu Firmware R16sfcpu R16sfcpu Firmware R32psfcpu R32psfcpu Firmware R32sfcpu R32sfcpu Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Mitsubishi

Published:

Updated: 2024-08-03T17:45:44.727Z

Reserved: 2020-12-17T00:00:00.000Z

Link: CVE-2021-20597

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-08-06T17:15:07.140

Modified: 2024-11-21T05:46:51.063

Link: CVE-2021-20597

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses