9.1
CVSSv3

CVE-2021-20597

Published: 06/08/2021 Updated: 24/05/2024
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated malicious user to login to the target unauthorizedly by sniffing network traffic and obtaining credentials when registering user information in the target or changing a password.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mitsubishielectric r08sfcpu firmware

mitsubishielectric r16sfcpu firmware

mitsubishielectric r32sfcpu firmware

mitsubishielectric r120sfcpu firmware

mitsubishielectric r08psfcpu firmware

mitsubishielectric r16psfcpu firmware

mitsubishielectric r32psfcpu firmware

mitsubishielectric r120psfcpu firmware

ICS Advisories