CVE-2021-20599: Critical severity mitsubishi electric r08sfcpu vulnerability
Cleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/32/120SFCPU firmware versions "26" and prior and MELSEC iQ-R series SIL2 Process CPU R08/16/32/120PSFCPU all versions allows a remote unauthenticated attacker to login to a target CPU module by obtaining credentials other than password.
Other sources
Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/32/120SFCPU firmware versions "26" and prior and MELSEC iQ-R series SIL2 Process CPU R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to a target CPU module by obtaining credentials other than password.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20599?
The severity of CVE-2021-20599 is high with a severity value of 7.5.
How does CVE-2021-20599 affect the MELSEC iQ-R series Safety CPU?
CVE-2021-20599 allows a remote unauthenticated attacker to login to a target CPU module by obtaining sensitive information through cleartext transmission.
Which firmware versions of MELSEC iQ-R series Safety CPU are affected by CVE-2021-20599?
CVE-2021-20599 affects MELSEC iQ-R series Safety CPU R08/16/32/120SFCPU firmware versions "26" and prior.
Is there a fix available for CVE-2021-20599?
Yes, a fix is available for CVE-2021-20599. Refer to the vendor's advisory for more information.
Where can I find more information about CVE-2021-20599?
More information about CVE-2021-20599 can be found in the references provided by JVN, CISA, and Mitsubishi Electric.