CVE Feed

    Dashboard / CVE / CVE-2021-20597

    CVE-2021-20597

    Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to the target unauthorizedly by sniffing network traffic and obtaining credentials when registering user information in the target or changing a password.

    Published:Aug 6, 2021
    Last Modified:Nov 21, 2024
    EPS:Aug 6, 2021
    EPSS Score:0.00888
    CVSS Score:9.1

    Affected Products

    Vendor
    Mitsubishielectric
    Product
    R08psfcpu
    Vendor
    Mitsubishielectric
    Product
    R08psfcpu Firmware
    Vendor
    Mitsubishielectric
    Product
    R08sfcpu
    Vendor
    Mitsubishielectric
    Product
    R08sfcpu Firmware
    Vendor
    Mitsubishielectric
    Product
    R120psfcpu
    Vendor
    Mitsubishielectric
    Product
    R120psfcpu Firmware
    Vendor
    Mitsubishielectric
    Product
    R120sfcpu
    Vendor
    Mitsubishielectric
    Product
    R120sfcpu Firmware
    Vendor
    Mitsubishielectric
    Product
    R16psfcpu
    Vendor
    Mitsubishielectric
    Product
    R16psfcpu Firmware
    Vendor
    Mitsubishielectric
    Product
    R16sfcpu
    Vendor
    Mitsubishielectric
    Product
    R16sfcpu Firmware
    Vendor
    Mitsubishielectric
    Product
    R32psfcpu
    Vendor
    Mitsubishielectric
    Product
    R32psfcpu Firmware
    Vendor
    Mitsubishielectric
    Product
    R32sfcpu
    Vendor
    Mitsubishielectric
    Product
    R32sfcpu Firmware

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High