PT-2023-6891 · Mitsubishi · Melsec-L Series+8

Published

2023-11-02

·

Updated

2025-12-16

·

CVE-2023-4699

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mitsubishi Electric Corporation MELSEC-F Series CPU modules (affected versions not specified) Mitsubishi Electric Corporation MELSEC iQ-F Series (affected versions not specified) Mitsubishi Electric Corporation MELSEC iQ-R series CPU modules (affected versions not specified) Mitsubishi Electric Corporation MELSEC iQ-R series (affected versions not specified) Mitsubishi Electric Corporation MELSEC iQ-L series (affected versions not specified) Mitsubishi Electric Corporation MELSEC Q series (affected versions not specified) Mitsubishi Electric Corporation MELSEC-L series (affected versions not specified) Mitsubishi Electric CNC M800V/M80V series (affected versions not specified) Mitsubishi Electric CNC M800/M80/E80 series (affected versions not specified) Mitsubishi Electric CNC M700V/M70V/E70 series (affected versions not specified)
Description The issue is related to insufficient authentication for critical functions, allowing a remote unauthenticated attacker to execute arbitrary commands by sending specific packets to the affected products. This could lead to disclosure or tampering with information by reading or writing control programs, or cause a denial-of-service (DoS) condition on the products by resetting the memory contents of the products to factory settings or resetting the products remotely.
Recommendations For Mitsubishi Electric Corporation MELSEC-F Series CPU modules, consider disabling remote access until a patch is available. For Mitsubishi Electric Corporation MELSEC iQ-F Series, restrict access to critical functions to minimize the risk of exploitation. For Mitsubishi Electric Corporation MELSEC iQ-R series CPU modules, MELSEC iQ-R series, MELSEC iQ-L series, MELSEC Q series, MELSEC-L series, Mitsubishi Electric CNC M800V/M80V series, Mitsubishi Electric CNC M800/M80/E80 series, and Mitsubishi Electric CNC M700V/M70V/E70 series, avoid using the affected products for critical operations until a fix is provided. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Verification of Data Authenticity

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2023-07906
CVE-2023-4699

Affected Products

Melsec-Q Series
Melsec Iq-F Series
Melsec-L Series
Melsec Iq-R Series
Melsec Iq-R Series Cpu Modules
Melsec-F Series Cpu Modules
Mitsubishi Electric Cnc M700V/M70V/E70 Series
Mitsubishi Electric Cnc M800/M80/E80 Series
Mitsubishi Electric Cnc M800V/M80V Series