#VU57377 Authorization bypass through user-controlled key in Mitsubishi Electric products - CVE-2021-20599

 

#VU57377 Authorization bypass through user-controlled key in Mitsubishi Electric products - CVE-2021-20599

Published: October 15, 2021


Vulnerability identifier: #VU57377
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2021-20599
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
MELSEC iQ-R 08 SFCPU
MELSEC iQ-R 16 SFCPU
MELSEC iQ-R 32 SFCPU
MELSEC iQ-R 120 SFCPU
MELSEC iQ-R 08 PSFCPU
MELSEC iQ-R 16 PSFCPU
MELSEC iQ-R 32 PSFCPU
MELSEC iQ-R 120 PSFCPU
Software vendor:
Mitsubishi Electric

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exist due to insufficient access authorization. A remote attacker can log in to the CPU module by obtaining credentials other than password.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links