#VU29221 Cleartext transmission of sensitive information in Mitsubishi Electric products - CVE-2020-14476
Published: June 24, 2020 / Updated: July 15, 2020
MELSEC iQ-R series
MELSEC iQ-F series
MELSEC Q series
MELSEC L series
MELSEC FX series
Mitsubishi Electric
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to software uses insecure communication channel to transmit sensitive information between the affected products and GX Works3/GX Works2. A remote attacker with ability to intercept network traffic can gain access to sensitive data, leading to unauthorized operation, and denial-of-service (DoS) attacks.