CVE-2021-20597
moderate-risk
Published 2021-08-06
Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to the target unauthorizedly by sniffing network traffic and obtaining credentials when registering user information in the target or changing a password.
Do I need to act?
-
0.89% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.1/10
Critical
NETWORK
/ LOW complexity
Affected Products (8)
R08Sfcpu Firmware
R16Sfcpu Firmware
R32Sfcpu Firmware
R120Sfcpu Firmware
R08Psfcpu Firmware
R16Psfcpu Firmware
R32Psfcpu Firmware
R120Psfcpu Firmware
Affected Vendors
References (6)
Third Party Advisory
https://jvn.jp/vu/JVNVU98578731/index.html
Third Party Advisory
https://jvn.jp/vu/JVNVU98578731/index.html
48
/ 100
moderate-risk
Severity
31/34 · Critical
Exploitability
3/34 · Minimal
Exposure
14/34 · Moderate