Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R08/16/32/120SFCPU all versions, R08/16/32/120PSFCPU all versions) allows a remote unauthenticated attacker to lockout a legitimate user by continuously trying login with incorrect password.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://jvn.jp/vu/JVNVU98578731/index.html | third party advisory |
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-010_en.pdf | vendor advisory |