Security Advisory

CVE-2021-20597

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-08-06 00:00:00
Last updated 2024-08-03 17:45:44
Assigner Mitsubishi
CVSS score not scored
State PUBLISHED

Description

Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to the target unauthorizedly by sniffing network traffic and obtaining credentials when registering user information in the target or changing a password.