Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to acquire legitimate user names registered in the module via brute-force attack on user names.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Mitsubishielectric
Subscribe
|
R08psfcpu
Subscribe
R08psfcpu Firmware
Subscribe
R08sfcpu
Subscribe
R08sfcpu Firmware
Subscribe
R120psfcpu
Subscribe
R120psfcpu Firmware
Subscribe
R120sfcpu
Subscribe
R120sfcpu Firmware
Subscribe
R16psfcpu
Subscribe
R16psfcpu Firmware
Subscribe
R16sfcpu
Subscribe
R16sfcpu Firmware
Subscribe
R32psfcpu
Subscribe
R32psfcpu Firmware
Subscribe
R32sfcpu
Subscribe
R32sfcpu Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-8012 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to acquire legitimate user names registered in the module via brute-force attack on user names. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Mitsubishi
Published:
Updated: 2024-08-03T17:45:44.726Z
Reserved: 2020-12-17T00:00:00
Link: CVE-2021-20594
No data.
Status : Modified
Published: 2021-08-06T17:15:07.103
Modified: 2024-11-21T05:46:50.623
Link: CVE-2021-20594
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD