PT-2021-8028 · Mitsubishi · Melsec Iq-R Series Cpu Modules
Published
2021-08-05
·
Updated
2021-08-27
·
CVE-2021-20598
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Mitsubishi Electric MELSEC iQ-R series CPU modules versions R08/16/32/120SFCPU all versions
Mitsubishi Electric MELSEC iQ-R series CPU modules versions R08/16/32/120PSFCPU all versions
Description
The issue is related to an overly restrictive account lockout mechanism in the Mitsubishi Electric MELSEC iQ-R series CPU modules. This allows a remote unauthenticated attacker to lock out a legitimate user by continuously trying to log in with an incorrect password. The exploitation of this issue can enable a remote attacker to block a user's account by sequentially entering a known username and incorrect password.
Recommendations
For Mitsubishi Electric MELSEC iQ-R series CPU modules versions R08/16/32/120SFCPU all versions, consider implementing a temporary workaround to limit the number of incorrect login attempts.
For Mitsubishi Electric MELSEC iQ-R series CPU modules versions R08/16/32/120PSFCPU all versions, restrict access to the login functionality until a fix is available.
As a temporary mitigation measure, consider disabling the login feature for the affected CPU modules until a patch is released.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Melsec Iq-R Series Cpu Modules