Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows cleartext transmission of sensitive information between CPU modules and GX Works3 and/or GX Works2 via unspecified vectors.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-003_en.pdf | vendor advisory |
https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2020-003.pdf | vendor advisory |
https://jvn.jp/en/vu/JVNVU91424496/index.html | third party advisory |