ICSA-21-250-01
·
Published 2024-04-18
·
View on CISA ICS-CERT ↗
Mitsubishi Electric MELSEC iQ-R Series
CVSS 7.4
HIGH
Risk Summary
Successful exploitation of these vulnerabilities could allow a remote attacker unauthorized access to legitimate usernames, CPU module access, or the ability to deny access to legitimate users.
CVEs (3)
Remediations
- Users of the affected products and versions may take measures through mitigations and workarounds. Mitsubishi Electric has released the fixed versions for CVE-2021-20594 and CVE-2021-20597 as shown below, but updating the product to the fixed version is not available.
- MELSEC iQ-R series Safety CPU R08/16/32/120SFCPU:Firmware versions "27" or later
- MELSEC iQ-R series SIL2 Process CPU R08/16/32/120PSFCPU:Firmware versions "12" or later
- Mitsubishi Electric recommends users take the following mitigation measures to minimize the risk of exploiting these vulnerabilities:
- Use a firewall or virtual private network (VPN), etc. to prevent unauthorized access when Internet access is required.
- Use within a LAN and block access from untrusted networks and hosts through firewalls.
- Use the IP filter function to restrict the accessible IP addresses. MELSEC iQ-R Ethernet User's Manual (Application) 1.13 Security "IP filter"
- Additional information about these vulnerabilities or Mitsubishi Electric's compensating control is available by contacting a Mitsubishi Electric representative.
- Users should refer to Mitsubishi Electric advisories 2021-008, 2021-009, and 2021-010 for further details.
- Register user information or change the password via USB. If you have already registered user information or changed the user's password via the network, change the password once via USB. This mitigation is applicable to CVE-2021-20597
Affected Vendors
Mitsubishi Electric Corporation
Affected Products (16)
Mitsubishi Electric Corporation
·
MELSEC iQ-R series Safety CPU R08SFCPU Firmware
<=26
Mitsubishi Electric Corporation
·
MELSEC iQ-R series Safety CPU R16SFCPU Firmware
<=26
Mitsubishi Electric Corporation
·
MELSEC iQ-R series Safety CPU R32SFCPU Firmware
<=26
Mitsubishi Electric Corporation
·
MELSEC iQ-R series Safety CPU R120SFCPU Firmware
<=26
Mitsubishi Electric Corporation
·
MELSEC iQ-R series Safety CPU R08SFCPU
vers:all/*
Mitsubishi Electric Corporation
·
MELSEC iQ-R series Safety CPU R16SFCPU
vers:all/*
Mitsubishi Electric Corporation
·
MELSEC iQ-R series Safety CPU R32SFCPU
vers:all/*
Mitsubishi Electric Corporation
·
MELSEC iQ-R series Safety CPU R120SFCPU
vers:all/*
Mitsubishi Electric Corporation
·
MELSEC iQ-R series SIL2 Process CPU R08PSFCPU Firmware
<=11
Mitsubishi Electric Corporation
·
MELSEC iQ-R series SIL2 Process CPU R16PSFCPU Firmware
<=11
Mitsubishi Electric Corporation
·
MELSEC iQ-R series SIL2 Process CPU R32PSFCPU Firmware
<=11
Mitsubishi Electric Corporation
·
MELSEC iQ-R series SIL2 Process CPU R120PSFCPU Firmware
<=11
Mitsubishi Electric Corporation
·
MELSEC iQ-R series SIL2 Process CPU R08PSFCPU
vers:all/*
Mitsubishi Electric Corporation
·
MELSEC iQ-R series SIL2 Process CPU R16PSFCPU
vers:all/*
Mitsubishi Electric Corporation
·
MELSEC iQ-R series SIL2 Process CPU R32PSFCPU
vers:all/*
Mitsubishi Electric Corporation
·
MELSEC iQ-R series SIL2 Process CPU R120PSFCPU
vers:all/*
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more