CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.1. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.
Original NVD Description
Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to the target unauthorizedly by sniffing network traffic and obtaining credentials when registering user information in the target or changing a password.
Related CVEs
Other vulnerabilities affecting the same vendor(s)