PT-2023-3766 · Mitsubishi · Melsec Iq-R Series Ethernet/Ip Module Rj71Eip91+1

Publicado

2023-06-01

·

Atualizado

2023-06-16

·

CVE-2023-2063

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 (affected versions not specified) MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP (affected versions not specified)
Description The issue is related to an unrestricted upload of files with dangerous types in the FTP function. This can allow a remote attacker to compromise the target system, potentially leading to information disclosure, tampering, deletion, or destruction via file upload/download. The attacker may exploit this for further attacks.
Recommendations For MELSEC iQ-R Series EtherNet/IP module RJ71EIP91, restrict access to the FTP function until a patch is available. For MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP, consider disabling the FTP function temporarily to minimize the risk of exploitation. Avoid using the FTP function for uploading or downloading files until the issue is resolved.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-04055
CVE-2023-2063

Produtos afetados

Melsec Iq-F Series Ethernet/Ip Module Fx5-Enet/Ip
Melsec Iq-R Series Ethernet/Ip Module Rj71Eip91