CVE-2021-20597: Critical severity mitsubishi electric r08sfcpu vulnerability
Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU all versions allows a remote unauthenticated attacker to login to the target unauthorizedly by sniffing network traffic and obtaining credentials when registering user information in the target or changing a password.
Other sources
Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to the target unauthorizedly by sniffing network traffic and obtaining credentials when registering user information in the target or changing a password.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules?
The vulnerability ID is CVE-2021-20597.
What is the severity rating of CVE-2021-20597?
The severity rating of CVE-2021-20597 is 9.1 (Critical).
Which software versions are affected by CVE-2021-20597?
The vulnerability affects Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior.
Is there a fix available for CVE-2021-20597?
Yes, Mitsubishi Electric has released a firmware update to address the vulnerability.
Where can I find more information about CVE-2021-20597?
You can find more information about CVE-2021-20597 in the following references: [Link 1](https://jvn.jp/vu/JVNVU98578731/index.html), [Link 2](https://www.cisa.gov/uscert/ics/advisories/icsa-21-250-01), [Link 3](https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-009_en.pdf).