PT-2021-8027 · Mitsubishi · Melsec Iq-R Series Safety Cpu Modules R08/16/32/120Sfcpu+1

Published

2021-08-05

·

Updated

2024-05-24

·

CVE-2021-20597

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions prior to 26 Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions prior to 11
Description The issue is related to insufficient protection of credentials, allowing a remote unauthenticated attacker to login to the target unauthorizedly by sniffing network traffic and obtaining credentials when registering user information in the target or changing a password.
Recommendations For Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions prior to 26, update the firmware to a version later than 26 to resolve the issue. For Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions prior to 11, update the firmware to a version later than 11 to resolve the issue. As a temporary workaround, consider restricting access to the network to minimize the risk of exploitation by sniffing network traffic.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2024-03607
CVE-2021-20597

Affected Products

Melsec Iq-R Series Sil2 Process Cpu Modules R08/16/32/120Psfcpu
Melsec Iq-R Series Safety Cpu Modules R08/16/32/120Sfcpu