35
CVE-2021-20597
—CVSS 3.1
9.1 critical
EPSS
2%p82
Published
()
Modified
Description
Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to the target unauthorizedly by sniffing network traffic and obtaining credentials when registering user information in the target or changing a password.
- Vendors
- mitsubishielectric
- Products
- r08sfcpu firmware, r16sfcpu firmware, r32sfcpu firmware, r120sfcpu firmware, r08psfcpu firmware, r16psfcpu firmware, r32psfcpu firmware, r120psfcpu firmware
- Weakness
- CWE-522
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N