PT-2023-3094 · Mitsubishi · Melsec Iq-R Series Ethernet/Ip Module Rj71Eip91+3

Published

2023-06-01

·

Updated

2024-10-31

·

CVE-2023-2062

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mitsubishi Electric Corporation EtherNet/IP configuration tools SW1DNN-EIPCT-BD and SW1DNN-EIPCTFX5-BD MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP
Description The issue is related to missing password field masking in the Mitsubishi Electric Corporation EtherNet/IP configuration tools, allowing a remote unauthenticated attacker to obtain the password for the MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and the MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP. This results in an authentication bypass, enabling the attacker to access the modules via FTP. The vulnerability is associated with insufficient protection of password input fields.
Recommendations For SW1DNN-EIPCT-BD and SW1DNN-EIPCTFX5-BD, consider implementing proper password field masking to prevent unauthorized access. For MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP, restrict FTP access until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03185
CVE-2023-2062

Affected Products

Melsec Iq-F Series Ethernet/Ip Module Fx5-Enet/Ip
Melsec Iq-R Series Ethernet/Ip Module Rj71Eip91
Sw1Dnn-Eipct-Bd
Sw1Dnn-Eipctfx5-Bd