PT-2023-1684 · Mitsubishi · Melsec Iq-F Series Fx5-Enet/Ip+5

Heea Go

+4

·

Published

2023-03-02

·

Updated

2023-06-21

·

CVE-2023-0457

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mitsubishi Electric Corporation MELSEC iQ-F Series versions all Mitsubishi Electric Corporation MELSEC iQ-R Series versions all Mitsubishi Electric Corporation MELSEC-Q Series versions all Mitsubishi Electric Corporation MELSEC-L Series versions all Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U CPU modules version all Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U(C) CPU modules version all Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UJ CPU modules version all Mitsubishi Electric Corporation MELSEC iQ-F Series FX5S CPU modules version all Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET version all Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP version all
Description The issue concerns a Plaintext Storage of a Password vulnerability, allowing a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into the FTP server or Web server.
Recommendations For Mitsubishi Electric Corporation MELSEC iQ-F Series, consider disabling the storage of plaintext passwords in project files until a patch is available. For Mitsubishi Electric Corporation MELSEC iQ-R Series, restrict access to the FTP server and Web server to minimize the risk of exploitation. For Mitsubishi Electric Corporation MELSEC-Q Series, avoid using plaintext credentials in project files until the issue is resolved. For Mitsubishi Electric Corporation MELSEC-L Series, restrict access to the FTP server and Web server to minimize the risk of exploitation. For Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U CPU modules, consider disabling the storage of plaintext passwords in project files until a patch is available. For Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U(C) CPU modules, restrict access to the FTP server and Web server to minimize the risk of exploitation. For Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UJ CPU modules, avoid using plaintext credentials in project files until the issue is resolved. For Mitsubishi Electric Corporation MELSEC iQ-F Series FX5S CPU modules, restrict access to the FTP server and Web server to minimize the risk of exploitation. For Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET, consider disabling the storage of plaintext passwords in project files until a patch is available. For Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP, restrict access to the FTP server and Web server to minimize the risk of exploitation.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2023-01255
CVE-2023-0457

Affected Products

Melsec Iq-F Series
Melsec Iq-F Series Fx5-Enet/Ip
Melsec Iq-F Series Fx5S Cpu Modules
Melsec Iq-R Series
Melsec-L Series
Melsec-Q Series