Vulnerabilities > CVE-2021-20599 - Unspecified vulnerability in Mitsubishielectric products
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/32/120SFCPU firmware versions "26" and prior and MELSEC iQ-R series SIL2 Process CPU R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to a target CPU module by obtaining credentials other than password.
Vulnerable Configurations
References
- https://jvn.jp/vu/JVNVU98578731
- https://jvn.jp/vu/JVNVU98578731
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-287-03
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-287-03
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-011_en.pdf
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-011_en.pdf