HIGH · 7.5

CVE-2023-0457

Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to...

Vulnerability Description

Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into FTP server or Web server.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
MitsubishielectricFx5Uc-32Mr\/Ds-Ts FirmwareAll versions
MitsubishielectricFx5Uc-32Mr\/Ds-Ts-
MitsubishielectricFx5Uc-32Mt\/D FirmwareAll versions
MitsubishielectricFx5Uc-32Mt\/D-
MitsubishielectricFx5Uc-32Mt\/Dss FirmwareAll versions
MitsubishielectricFx5Uc-32Mt\/Dss-
MitsubishielectricFx5Uc-32Mt\/Dss-Ts FirmwareAll versions
MitsubishielectricFx5Uc-32Mt\/Dss-Ts-
MitsubishielectricFx5Uc-32Mt\/Ds-Ts FirmwareAll versions
MitsubishielectricFx5Uc-32Mt\/Ds-Ts-
MitsubishielectricFx5Uc-64Mt\/D FirmwareAll versions
MitsubishielectricFx5Uc-64Mt\/D-
MitsubishielectricFx5Uc-64Mt\/Dss FirmwareAll versions
MitsubishielectricFx5Uc-64Mt\/Dss-
MitsubishielectricFx5Uc-96Mt\/D FirmwareAll versions
MitsubishielectricFx5Uc-96Mt\/D-
MitsubishielectricFx5Uc-96Mt\/Dss FirmwareAll versions
MitsubishielectricFx5Uc-96Mt\/Dss-
MitsubishielectricFx5Uj-24Mr\/Es FirmwareAll versions
MitsubishielectricFx5Uj-24Mr\/Es-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-0457?

CVE-2023-0457 is a vulnerability with a CVSS score of 7.5 (HIGH). Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to...

How severe is CVE-2023-0457?

CVE-2023-0457 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-0457?

Check the references section above for vendor advisories and patch information. Affected products include: Mitsubishielectric Fx5Uc-32Mr\/Ds-Ts Firmware, Mitsubishielectric Fx5Uc-32Mr\/Ds-Ts, Mitsubishielectric Fx5Uc-32Mt\/D Firmware, Mitsubishielectric Fx5Uc-32Mt\/D, Mitsubishielectric Fx5Uc-32Mt\/Dss Firmware.