PT-2023-1684 · Mitsubishi · Melsec Iq-F Series Fx5-Enet/Ip+5

·

CVE-2023-0457

·

Published

2023-03-02

·

Updated

2023-06-21

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mitsubishi Electric Corporation MELSEC iQ-F Series versions all Mitsubishi Electric Corporation MELSEC iQ-R Series versions all Mitsubishi Electric Corporation MELSEC-Q Series versions all Mitsubishi Electric Corporation MELSEC-L Series versions all Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U CPU modules version all Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U(C) CPU modules version all Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UJ CPU modules version all Mitsubishi Electric Corporation MELSEC iQ-F Series FX5S CPU modules version all Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET version all Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP version all
Description The issue concerns a Plaintext Storage of a Password vulnerability, allowing a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into the FTP server or Web server.
Recommendations For Mitsubishi Electric Corporation MELSEC iQ-F Series, consider disabling the storage of plaintext passwords in project files until a patch is available. For Mitsubishi Electric Corporation MELSEC iQ-R Series, restrict access to the FTP server and Web server to minimize the risk of exploitation. For Mitsubishi Electric Corporation MELSEC-Q Series, avoid using plaintext credentials in project files until the issue is resolved. For Mitsubishi Electric Corporation MELSEC-L Series, restrict access to the FTP server and Web server to minimize the risk of exploitation. For Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U CPU modules, consider disabling the storage of plaintext passwords in project files until a patch is available. For Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U(C) CPU modules, restrict access to the FTP server and Web server to minimize the risk of exploitation. For Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UJ CPU modules, avoid using plaintext credentials in project files until the issue is resolved. For Mitsubishi Electric Corporation MELSEC iQ-F Series FX5S CPU modules, restrict access to the FTP server and Web server to minimize the risk of exploitation. For Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET, consider disabling the storage of plaintext passwords in project files until a patch is available. For Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP, restrict access to the FTP server and Web server to minimize the risk of exploitation.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01255
CVE-2023-0457

Affected Products

Melsec Iq-F Series
Melsec Iq-F Series Fx5-Enet/Ip
Melsec Iq-F Series Fx5S Cpu Modules
Melsec Iq-R Series
Melsec-L Series
Melsec-Q Series