Vulnerability Description
Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to the target unauthorizedly by sniffing network traffic and obtaining credentials when registering user information in the target or changing a password.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mitsubishielectric | R08Sfcpu Firmware | All versions |
| Mitsubishielectric | R08Sfcpu | - |
| Mitsubishielectric | R16Sfcpu Firmware | All versions |
| Mitsubishielectric | R16Sfcpu | - |
| Mitsubishielectric | R32Sfcpu Firmware | All versions |
| Mitsubishielectric | R32Sfcpu | - |
| Mitsubishielectric | R120Sfcpu Firmware | All versions |
| Mitsubishielectric | R120Sfcpu | - |
| Mitsubishielectric | R08Psfcpu Firmware | All versions |
| Mitsubishielectric | R08Psfcpu | - |
| Mitsubishielectric | R16Psfcpu Firmware | All versions |
| Mitsubishielectric | R16Psfcpu | - |
| Mitsubishielectric | R32Psfcpu Firmware | All versions |
| Mitsubishielectric | R32Psfcpu | - |
| Mitsubishielectric | R120Psfcpu Firmware | All versions |
| Mitsubishielectric | R120Psfcpu | - |
Related Weaknesses (CWE)
References
- https://jvn.jp/vu/JVNVU98578731/index.htmlThird Party Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-250-01
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-009_en.pdfVendor Advisory
- https://jvn.jp/vu/JVNVU98578731/index.htmlThird Party Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-250-01
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-009_en.pdfVendor Advisory
FAQ
What is CVE-2021-20597?
CVE-2021-20597 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R ...
How severe is CVE-2021-20597?
CVE-2021-20597 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-20597?
Check the references section above for vendor advisories and patch information. Affected products include: Mitsubishielectric R08Sfcpu Firmware, Mitsubishielectric R08Sfcpu, Mitsubishielectric R16Sfcpu Firmware, Mitsubishielectric R16Sfcpu, Mitsubishielectric R32Sfcpu Firmware.