CVE-2021-20599
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/32/120SFCPU firmware versions "26" and prior and MELSEC iQ-R series SIL2 Process CPU R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to a target CPU module by obtaining credentials other than password.
La vulnerabilidad de transmisión de texto claro de información sensible en las versiones de firmware "26" y anteriores de la CPU de seguridad R08/16/32/120SFCPU de la serie iQ-R de MELSEC y en la CPU de proceso SIL2 R08/16/32/120PSFCPU de la serie iQ-R de MELSEC, en todas sus versiones, permite que un atacante remoto no autenticado inicie sesión en un módulo de CPU objetivo obteniendo credenciales distintas de la contraseña
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2020-12-17 CVE Reserved
- 2021-10-14 CVE Published
- 2024-06-29 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-319: Cleartext Transmission of Sensitive Information
- CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
- CAPEC-115: Authentication Bypass
References (3)
URL | Tag | Source |
---|---|---|
https://jvn.jp/vu/JVNVU98578731 | Government Resource | |
https://www.cisa.gov/uscert/ics/advisories/icsa-21-287-03 | Government Resource |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-011_en.pdf | 2024-04-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mitsubishielectric Search vendor "Mitsubishielectric" | R08sfcpu Firmware Search vendor "Mitsubishielectric" for product "R08sfcpu Firmware" | * | - |
Affected
| in | Mitsubishielectric Search vendor "Mitsubishielectric" | R08sfcpu Search vendor "Mitsubishielectric" for product "R08sfcpu" | - | - |
Safe
|
Mitsubishielectric Search vendor "Mitsubishielectric" | R16sfcpu Firmware Search vendor "Mitsubishielectric" for product "R16sfcpu Firmware" | * | - |
Affected
| in | Mitsubishielectric Search vendor "Mitsubishielectric" | R16sfcpu Search vendor "Mitsubishielectric" for product "R16sfcpu" | - | - |
Safe
|
Mitsubishielectric Search vendor "Mitsubishielectric" | R32sfcpu Firmware Search vendor "Mitsubishielectric" for product "R32sfcpu Firmware" | * | - |
Affected
| in | Mitsubishielectric Search vendor "Mitsubishielectric" | R32sfcpu Search vendor "Mitsubishielectric" for product "R32sfcpu" | - | - |
Safe
|
Mitsubishielectric Search vendor "Mitsubishielectric" | R120sfcpu Firmware Search vendor "Mitsubishielectric" for product "R120sfcpu Firmware" | * | - |
Affected
| in | Mitsubishielectric Search vendor "Mitsubishielectric" | R120sfcpu Search vendor "Mitsubishielectric" for product "R120sfcpu" | - | - |
Safe
|
Mitsubishielectric Search vendor "Mitsubishielectric" | R08psfcpu Firmware Search vendor "Mitsubishielectric" for product "R08psfcpu Firmware" | * | - |
Affected
| in | Mitsubishielectric Search vendor "Mitsubishielectric" | R08psfcpu Search vendor "Mitsubishielectric" for product "R08psfcpu" | - | - |
Safe
|
Mitsubishielectric Search vendor "Mitsubishielectric" | R16psfcpu Firmware Search vendor "Mitsubishielectric" for product "R16psfcpu Firmware" | * | - |
Affected
| in | Mitsubishielectric Search vendor "Mitsubishielectric" | R16psfcpu Search vendor "Mitsubishielectric" for product "R16psfcpu" | - | - |
Safe
|
Mitsubishielectric Search vendor "Mitsubishielectric" | R32psfcpu Firmware Search vendor "Mitsubishielectric" for product "R32psfcpu Firmware" | * | - |
Affected
| in | Mitsubishielectric Search vendor "Mitsubishielectric" | R32psfcpu Search vendor "Mitsubishielectric" for product "R32psfcpu" | - | - |
Safe
|
Mitsubishielectric Search vendor "Mitsubishielectric" | R120psfcpu Firmware Search vendor "Mitsubishielectric" for product "R120psfcpu Firmware" | * | - |
Affected
| in | Mitsubishielectric Search vendor "Mitsubishielectric" | R120psfcpu Search vendor "Mitsubishielectric" for product "R120psfcpu" | - | - |
Safe
|