This content is restricted.
Brief
Summary:
A vulnerability has been discovered in the MELSEC iQ-R Series Safety CPU and SIL2 Process CPU modules from Mitsubishi Electric, which allows a non-administrator user to disclose the credentials (user ID and password) of a user with a lower access level than themselves. The vulnerability, rated 6.5 on the CVSS v3 scale, can be exploited remotely with low attack complexity. The affected products include various versions of the MELSEC iQ-R Series Safety CPU and SIL2 Process CPU modules. To mitigate this vulnerability, Mitsubishi Electric recommends enabling specific features in GX Works3 and restricting access to the affected product and connected devices.
Highlights content goes here...
This content is restricted.
