CVE-2021-20598: Medium severity mitsubishi electric r08sfcpu vulnerability
Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R08/16/32/120SFCPU all versions, R08/16/32/120PSFCPU all versions) allows a remote unauthenticated attacker to lockout a legitimate user by continuously trying login with incorrect password.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2021-20598.
What is the affected software?
The affected software is Mitsubishi Electric MELSEC iQ-R series CPU modules (R08/16/32/120SFCPU all versions, R08/16/32/120PSFCPU all versions).
How severe is CVE-2021-20598 vulnerability?
CVE-2021-20598 has a severity rating of 5.3 (medium).
How does the vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules work?
The vulnerability allows a remote unauthenticated attacker to lockout a legitimate user by continuously trying to login with incorrect passwords.
Are there any patches or fixes available for CVE-2021-20598?
Yes, patches and fixes for CVE-2021-20598 are available. Please refer to the official Mitsubishi Electric PSIRT website for more information.