QID 590650

Date Published: 2022-03-17

QID 590650: Mitsubishi Electric MELSEC iQ-R Series Authorization Bypass Through User-controlled Key Vulnerability (ICSA-21-287-03)

AFFECTED PRODUCTS
Mitsubishi Electric reports the vulnerability affects the following MELSEC Safety CPU/SIL2 Process CPU Modules:
R08/16/32/120SFCPU: all versions
R08/16/32/120PSFCPU: all versions

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability could allow a remote attacker to be able to log in to the CPU module by obtaining credentials.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-287-03 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590650

    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-287-03 URL Logo www.us-cert.gov/ics/advisories/ICSA-21-287-03