Account Lockout Bypass Vulnerability in Mitsubishi Electric MELSEC iQ-R Series CPU Modules

Account Lockout Bypass Vulnerability in Mitsubishi Electric MELSEC iQ-R Series CPU Modules

CVE-2021-20598 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R08/16/32/120SFCPU all versions, R08/16/32/120PSFCPU all versions) allows a remote unauthenticated attacker to lockout a legitimate user by continuously trying login with incorrect password.

Learn more about our User Device Pen Test.