Improper Access Control in Mitsubishi Electric products - CVE-2020-5656

 

Improper Access Control in Mitsubishi Electric products - CVE-2020-5656

Published: November 2, 2020


Vulnerability identifier: #VU48075
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-5656
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. A remote attacker can bypass implemented security restrictions and gain unauthorized access to the application.

This vulnerability affects the following modules of MELSEC iQ-R Series: 

  • EtherNet/IP Network Interface Module, RJ71EIP91: First 2 digits of serial number are 02 or before.
  • PROFINET IO Controller Module, RJ71PN92: First 2 digits of serial number are 01 or before
  • High Speed Data Logger Module,RD81DL96: First 2 digits of serial number are 08 or before
  • MES Interface Module, RD81MES96N: First 2 digits of serial number are 04 or before
  • OPC UA Server Module, RD81OPC96: First 2 digits of serial number are 04 or before 


Affected software

MELSEC iQ-R EtherNet/IP Network Interface Module
MELSEC iQ-R PROFINET IO Controller Module
MELSEC iQ-R High Speed Data Logger Module
MELSEC iQ-R MES Interface Module
MELSEC iQ-R OPC UA Server Module

How to mitigate CVE-2020-5656

Install updates from vendor's website.

MELSEC iQ-R EtherNet/IP Network Interface Module - update to 03
MELSEC iQ-R PROFINET IO Controller Module - update to 02
MELSEC iQ-R High Speed Data Logger Module - update to 09
MELSEC iQ-R MES Interface Module - update to 05
MELSEC iQ-R OPC UA Server Module - update to 05

External References

Related Security Bulletins