CVE-2021-20594
moderate-risk
Published 2021-08-06
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to acquire legitimate user names registered in the module via brute-force attack on user names.
Do I need to act?
-
0.86% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
Affected Products (8)
R08Sfcpu Firmware
R16Sfcpu Firmware
R32Sfcpu Firmware
R120Sfcpu Firmware
R08Psfcpu Firmware
R16Psfcpu Firmware
R32Psfcpu Firmware
R120Psfcpu Firmware
Affected Vendors
References (6)
Third Party Advisory
https://jvn.jp/vu/JVNVU98578731/index.html
Third Party Advisory
https://jvn.jp/vu/JVNVU98578731/index.html
43
/ 100
moderate-risk
Severity
26/34 · High
Exploitability
3/34 · Minimal
Exposure
14/34 · Moderate