Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to the target unauthorizedly by sniffing network traffic and obtaining credentials when registering user information in the target or changing a password.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Mitsubishielectric
Subscribe
|
R08psfcpu
Subscribe
R08psfcpu Firmware
Subscribe
R08sfcpu
Subscribe
R08sfcpu Firmware
Subscribe
R120psfcpu
Subscribe
R120psfcpu Firmware
Subscribe
R120sfcpu
Subscribe
R120sfcpu Firmware
Subscribe
R16psfcpu
Subscribe
R16psfcpu Firmware
Subscribe
R16sfcpu
Subscribe
R16sfcpu Firmware
Subscribe
R32psfcpu
Subscribe
R32psfcpu Firmware
Subscribe
R32sfcpu
Subscribe
R32sfcpu Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-8015 | Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to the target unauthorizedly by sniffing network traffic and obtaining credentials when registering user information in the target or changing a password. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Mitsubishi
Published:
Updated: 2024-08-03T17:45:44.727Z
Reserved: 2020-12-17T00:00:00
Link: CVE-2021-20597
No data.
Status : Modified
Published: 2021-08-06T17:15:07.140
Modified: 2024-11-21T05:46:51.063
Link: CVE-2021-20597
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD