PT-2023-6278 · Mitsubishi · Melsec-L Series

Published

2023-10-12

·

Updated

2023-10-23

·

CVE-2023-4562

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mitsubishi Electric Corporation MELSEC-F Series main modules (affected versions not specified)
Description The issue is related to an improper authentication vulnerability. This vulnerability allows a remote unauthenticated attacker to obtain sequence programs from the product, write malicious sequence programs, or write improper data in the product without authentication by sending illegitimate messages. The exploitation of this vulnerability may allow an attacker to bypass existing security restrictions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-06988
CVE-2023-4562

Affected Products

Melsec-L Series