PT-2023-3766 · Mitsubishi · Melsec Iq-R Series Ethernet/Ip Module Rj71Eip91+1
Published
2023-06-01
·
Updated
2023-06-16
·
CVE-2023-2063
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 (affected versions not specified)
MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP (affected versions not specified)
Description
The issue is related to an unrestricted upload of files with dangerous types in the FTP function. This can allow a remote attacker to compromise the target system, potentially leading to information disclosure, tampering, deletion, or destruction via file upload/download. The attacker may exploit this for further attacks.
Recommendations
For MELSEC iQ-R Series EtherNet/IP module RJ71EIP91, restrict access to the FTP function until a patch is available.
For MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP, consider disabling the FTP function temporarily to minimize the risk of exploitation.
Avoid using the FTP function for uploading or downloading files until the issue is resolved.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Melsec Iq-F Series Ethernet/Ip Module Fx5-Enet/Ip
Melsec Iq-R Series Ethernet/Ip Module Rj71Eip91