Critical severity9.1NVD Advisory· Published Oct 14, 2021· Updated Jun 17, 2026
CVE-2021-20599
CVE-2021-20599
Description
Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/32/120SFCPU firmware versions "26" and prior and MELSEC iQ-R series SIL2 Process CPU R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to a target CPU module by obtaining credentials other than password.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18- cpe:2.3:o:mitsubishielectric:r08psfcpu_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:mitsubishielectric:r08sfcpu_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:mitsubishielectric:r120psfcpu_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:mitsubishielectric:r120sfcpu_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:mitsubishielectric:r16psfcpu_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:mitsubishielectric:r16sfcpu_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:mitsubishielectric:r32psfcpu_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:mitsubishielectric:r32sfcpu_firmware:*:*:*:*:*:*:*:*
- Range: <=11
<=26+ 4 more
- (no CPE)range: <=26
- (no CPE)range: Firmware versions "26" and prior
- (no CPE)range: Firmware versions "26" and prior
- (no CPE)range: Firmware versions "26" and prior
- (no CPE)range: Firmware versions "26" and prior
- Mitsubishi Electric Corporation/MELSEC iQ-R Series SIL2 Process CPU R08PSFCPUv5Range: Firmware versions "11" and prior
- Mitsubishi Electric Corporation/MELSEC iQ-R series SIL2 Process CPU R120PSFCPUv5Range: Firmware versions "11" and prior
- Mitsubishi Electric Corporation/MELSEC iQ-R series SIL2 Process CPU R16PSFCPUv5Range: Firmware versions "11" and prior
- Mitsubishi Electric Corporation/MELSEC iQ-R series SIL2 Process CPU R32PSFCPUv5Range: Firmware versions "11" and prior
Patches
Vulnerability mechanics
References
3- jvn.jp/vu/JVNVU98578731nvdThird Party Advisory
- www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-011_en.pdfnvdVendor Advisory
- www.cisa.gov/uscert/ics/advisories/icsa-21-287-03nvd
News mentions
0No linked articles in our index yet.