CVE-2021-20597
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to the target unauthorizedly by sniffing network traffic and obtaining credentials when registering user information in the target or changing a password.
La vulnerabilidad de credenciales insuficientemente protegidas en los módulos de CPU de seguridad de la serie MELSEC iQ-R de Mitsubishi Electric R08/16/32/120SFCPU, versiones de firmware "26" y anteriores, y en los módulos de CPU de proceso SIL2 de la serie MELSEC iQ-R de Mitsubishi Electric R08/16/32/120PSFCPU, todas las versiones, permite que un atacante remoto no autenticado inicie sesión en el objetivo de forma no autorizada mediante el olfateo del tráfico de red y la obtención de credenciales al registrar información de usuario en el objetivo o al cambiar una contraseña
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-12-17 CVE Reserved
- 2021-08-06 CVE Published
- 2024-04-21 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-522: Insufficiently Protected Credentials
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://jvn.jp/vu/JVNVU98578731/index.html | Third Party Advisory | |
https://www.cisa.gov/uscert/ics/advisories/icsa-21-250-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-009_en.pdf | 2024-05-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mitsubishielectric Search vendor "Mitsubishielectric" | R08sfcpu Firmware Search vendor "Mitsubishielectric" for product "R08sfcpu Firmware" | * | - |
Affected
| in | Mitsubishielectric Search vendor "Mitsubishielectric" | R08sfcpu Search vendor "Mitsubishielectric" for product "R08sfcpu" | - | - |
Safe
|
Mitsubishielectric Search vendor "Mitsubishielectric" | R16sfcpu Firmware Search vendor "Mitsubishielectric" for product "R16sfcpu Firmware" | * | - |
Affected
| in | Mitsubishielectric Search vendor "Mitsubishielectric" | R16sfcpu Search vendor "Mitsubishielectric" for product "R16sfcpu" | - | - |
Safe
|
Mitsubishielectric Search vendor "Mitsubishielectric" | R32sfcpu Firmware Search vendor "Mitsubishielectric" for product "R32sfcpu Firmware" | * | - |
Affected
| in | Mitsubishielectric Search vendor "Mitsubishielectric" | R32sfcpu Search vendor "Mitsubishielectric" for product "R32sfcpu" | - | - |
Safe
|
Mitsubishielectric Search vendor "Mitsubishielectric" | R120sfcpu Firmware Search vendor "Mitsubishielectric" for product "R120sfcpu Firmware" | * | - |
Affected
| in | Mitsubishielectric Search vendor "Mitsubishielectric" | R120sfcpu Search vendor "Mitsubishielectric" for product "R120sfcpu" | - | - |
Safe
|
Mitsubishielectric Search vendor "Mitsubishielectric" | R08psfcpu Firmware Search vendor "Mitsubishielectric" for product "R08psfcpu Firmware" | * | - |
Affected
| in | Mitsubishielectric Search vendor "Mitsubishielectric" | R08psfcpu Search vendor "Mitsubishielectric" for product "R08psfcpu" | - | - |
Safe
|
Mitsubishielectric Search vendor "Mitsubishielectric" | R16psfcpu Firmware Search vendor "Mitsubishielectric" for product "R16psfcpu Firmware" | * | - |
Affected
| in | Mitsubishielectric Search vendor "Mitsubishielectric" | R16psfcpu Search vendor "Mitsubishielectric" for product "R16psfcpu" | - | - |
Safe
|
Mitsubishielectric Search vendor "Mitsubishielectric" | R32psfcpu Firmware Search vendor "Mitsubishielectric" for product "R32psfcpu Firmware" | * | - |
Affected
| in | Mitsubishielectric Search vendor "Mitsubishielectric" | R32psfcpu Search vendor "Mitsubishielectric" for product "R32psfcpu" | - | - |
Safe
|
Mitsubishielectric Search vendor "Mitsubishielectric" | R120psfcpu Firmware Search vendor "Mitsubishielectric" for product "R120psfcpu Firmware" | * | - |
Affected
| in | Mitsubishielectric Search vendor "Mitsubishielectric" | R120psfcpu Search vendor "Mitsubishielectric" for product "R120psfcpu" | - | - |
Safe
|