PT-2021-8030 · Mitsubishi · Melsec Iq-R Series Sil2 Process Cpu Modules R08/16/32/120Psfcpu+1
Ivan Speziale
·
Published
2021-08-05
·
Updated
2024-05-24
·
CVE-2021-20594
CVSS v2.0
5.4
Medium
| Vector | AV:N/AC:H/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MELSEC iQ-R Series Safety CPU modules R08/16/32/120SFCPU firmware versions prior to 26
MELSEC iQ-R Series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions prior to 11
Description
The issue is related to the exposure of sensitive information to unauthorized actors due to a lack of protection for service data. This can allow a remote attacker to gain unauthorized access to protected information. Specifically, it enables a remote unauthenticated attacker to acquire legitimate user names registered in the module via a brute-force attack on user names.
Recommendations
For MELSEC iQ-R Series Safety CPU modules R08/16/32/120SFCPU firmware versions prior to 26, update the firmware to version 26 or later.
For MELSEC iQ-R Series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions prior to 11, update the firmware to version 11 or later.
As a temporary workaround, consider restricting access to the modules to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Melsec Iq-R Series Sil2 Process Cpu Modules R08/16/32/120Psfcpu
Melsec Iq-R Series Safety Cpu Modules R08/16/32/120Sfcpu