cve/2021/CVE-2021-20599.md

26 lines
2.0 KiB
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2021-20599](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20599)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20SIL2%20Process%20CPU%20R08PSFCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20Safety%20CPU%20R08SFCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20series%20SIL2%20Process%20CPU%20R120PSFCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20series%20SIL2%20Process%20CPU%20R16PSFCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20series%20SIL2%20Process%20CPU%20R32PSFCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20series%20Safety%20CPU%20R120SFCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20series%20Safety%20CPU%20R16SFCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20series%20Safety%20CPU%20R32SFCPU&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20Firmware%20versions%20%2211%22%20and%20prior%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20Firmware%20versions%20%2226%22%20and%20prior%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-319%20Cleartext%20Transmission%20of%20Sensitive%20Information&color=brighgreen)
### Description
Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/32/120SFCPU firmware versions "26" and prior and MELSEC iQ-R series SIL2 Process CPU R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to a target CPU module by obtaining credentials other than password.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/NozomiNetworks/blackhat23-melsoft