Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/32/120SFCPU firmware versions "26" and prior and MELSEC iQ-R series SIL2 Process CPU R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to a target CPU module by obtaining credentials other than password.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-011_en.pdf | vendor advisory |
https://jvn.jp/vu/JVNVU98578731 | third party advisory government resource |
https://www.cisa.gov/uscert/ics/advisories/icsa-21-287-03 | government resource |