CVE-2016-8370: Weak Encryption
An issue was discovered in Mitsubishi Electric Automation MELSEC-Q series Ethernet interface modules QJ71E71-100, all versions, QJ71E71-B5, all versions, and QJ71E71-B2, all versions. Weakly encrypted passwords are transmitted to a MELSEC-Q PLC.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8370?
CVE-2016-8370 is rated as a medium severity vulnerability due to the transmission of weakly encrypted passwords.
How do I fix CVE-2016-8370?
To mitigate CVE-2016-8370, update the firmware of the affected Mitsubishi Electric Automation MELSEC-Q series Ethernet interface modules to the latest version that addresses the issue.
What devices are affected by CVE-2016-8370?
CVE-2016-8370 affects the Mitsubishi Electric Automation MELSEC-Q series Ethernet interface modules QJ71E71-100, QJ71E71-B5, and QJ71E71-B2.
What is the impact of CVE-2016-8370?
The impact of CVE-2016-8370 is that attackers could potentially intercept and decipher weakly encrypted passwords, leading to unauthorized access.
Is there a workaround for CVE-2016-8370?
Currently, the recommended workaround for CVE-2016-8370 is to disable remote access to the affected modules when possible until the firmware is updated.