PT-2023-3094 · Mitsubishi · Melsec Iq-R Series Ethernet/Ip Module Rj71Eip91+3
Published
2023-06-01
·
Updated
2024-10-31
·
CVE-2023-2062
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mitsubishi Electric Corporation EtherNet/IP configuration tools SW1DNN-EIPCT-BD and SW1DNN-EIPCTFX5-BD
MELSEC iQ-R Series EtherNet/IP module RJ71EIP91
MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP
Description
The issue is related to missing password field masking in the Mitsubishi Electric Corporation EtherNet/IP configuration tools, allowing a remote unauthenticated attacker to obtain the password for the MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and the MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP. This results in an authentication bypass, enabling the attacker to access the modules via FTP. The vulnerability is associated with insufficient protection of password input fields.
Recommendations
For SW1DNN-EIPCT-BD and SW1DNN-EIPCTFX5-BD, consider implementing proper password field masking to prevent unauthorized access.
For MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP, restrict FTP access until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Melsec Iq-F Series Ethernet/Ip Module Fx5-Enet/Ip
Melsec Iq-R Series Ethernet/Ip Module Rj71Eip91
Sw1Dnn-Eipct-Bd
Sw1Dnn-Eipctfx5-Bd