First published: Fri Aug 06 2021(Updated: )
Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R08/16/32/120SFCPU all versions, R08/16/32/120PSFCPU all versions) allows a remote unauthenticated attacker to lockout a legitimate user by continuously trying login with incorrect password.
Credit: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishielectric R08sfcpu Firmware | ||
Mitsubishielectric R08sfcpu | ||
Mitsubishielectric R16sfcpu Firmware | ||
Mitsubishielectric R16sfcpu | ||
Mitsubishielectric R32sfcpu Firmware | ||
Mitsubishielectric R32sfcpu | ||
Mitsubishielectric R120sfcpu Firmware | ||
Mitsubishielectric R120sfcpu | ||
Mitsubishielectric R08psfcpu Firmware | ||
Mitsubishielectric R08psfcpu | ||
Mitsubishielectric R16psfcpu Firmware | ||
Mitsubishielectric R16psfcpu | ||
Mitsubishielectric R32psfcpu Firmware | ||
Mitsubishielectric R32psfcpu | ||
Mitsubishielectric R120psfcpu Firmware | ||
Mitsubishielectric R120psfcpu |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2021-20598.
The affected software is Mitsubishi Electric MELSEC iQ-R series CPU modules (R08/16/32/120SFCPU all versions, R08/16/32/120PSFCPU all versions).
CVE-2021-20598 has a severity rating of 5.3 (medium).
The vulnerability allows a remote unauthenticated attacker to lockout a legitimate user by continuously trying to login with incorrect passwords.
Yes, patches and fixes for CVE-2021-20598 are available. Please refer to the official Mitsubishi Electric PSIRT website for more information.