Medium severity5.3NVD Advisory· Published Aug 6, 2021· Updated Jun 17, 2026
CVE-2021-20598
CVE-2021-20598
Description
Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R08/16/32/120SFCPU all versions, R08/16/32/120PSFCPU all versions) allows a remote unauthenticated attacker to lockout a legitimate user by continuously trying login with incorrect password.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- Range: all versions
- Mitsubishi Electric/MELSEC iQ-R series CPU modulesdescription
- cpe:2.3:o:mitsubishielectric:r08sfcpu_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:mitsubishielectric:r16sfcpu_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:mitsubishielectric:r32sfcpu_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:mitsubishielectric:r120sfcpu_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:mitsubishielectric:r08psfcpu_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:mitsubishielectric:r16psfcpu_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:mitsubishielectric:r32psfcpu_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:mitsubishielectric:r120psfcpu_firmware:*:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- jvn.jp/vu/JVNVU98578731/index.htmlnvdThird Party Advisory
- www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-010_en.pdfnvdVendor Advisory
News mentions
0No linked articles in our index yet.