CVE-2020-5594

Severity CVSS v4.0:
Pending analysis
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
23/06/2020
Last modified:
01/07/2020

Description

Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows cleartext transmission of sensitive information between CPU modules and GX Works3 and/or GX Works2 via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:mitsubishielectric:melsec_iq-r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:melsec_iq-r:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:melsec_iq-f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:melsec_iq-f:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:melsec-q_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:melsec-q:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:melsec-l_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:melsec-l:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:melsec-fx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:melsec-fx:-:*:*:*:*:*:*:*