Lucene search

K
cvelistMitsubishiCVELIST:CVE-2021-20594
HistoryAug 06, 2021 - 12:00 a.m.

CVE-2021-20594

2021-08-0600:00:00
Mitsubishi
www.cve.org
9
vulnerability
mitsubishi electric
melsec iq-r
sensitive information
unauthorized actor
brute-force attack
user names

AI Score

8.6

Confidence

High

EPSS

0.004

Percentile

73.9%

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions “26” and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions “11” and prior allows a remote unauthenticated attacker to acquire legitimate user names registered in the module via brute-force attack on user names.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU; Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions \"26\" and prior"
      },
      {
        "status": "affected",
        "version": "Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions \"11\" and prior"
      }
    ]
  }
]

AI Score

8.6

Confidence

High

EPSS

0.004

Percentile

73.9%

Related for CVELIST:CVE-2021-20594