MEDIUM🇵🇱 Wersja polska

CVE-2023-2061

CVSS 6.2v3.1pub. 2023-06-02upd. 2024-11-21

Use of Hard-coded Password vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to obtain a hard-coded password and access to the module via FTP.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Mitsubishielectric Fx5 Enet\/ip

    HW
    Mitsubishielectric
    all versions
  • Mitsubishielectric Fx5 Enet\/ip Firmware

    OS
    Mitsubishielectric
    all versions
  • Mitsubishielectric Rj71eip91

    HW
    Mitsubishielectric
    all versions
  • Mitsubishielectric Rj71eip91 Firmware

    OS
    Mitsubishielectric
    all versions
  • Mitsubishielectric Sw1dnn Eipct Bd

    HW
    Mitsubishielectric
    all versions
  • Mitsubishielectric Sw1dnn Eipct Bd Firmware

    OS
    Mitsubishielectric
    all versions
  • Mitsubishielectric Sw1dnn Eipctfx5 Bd

    HW
    Mitsubishielectric
    all versions
  • Mitsubishielectric Sw1dnn Eipctfx5 Bd Firmware

    OS
    Mitsubishielectric
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2020-16226CRITICAL9.8PL ✓same product

Podatność na podszywanie się pod urządzenie w produktach Mitsubishi Electric — RCE

CVE-2023-2060HIGH7.5same product

Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series...

CVE-2023-0457HIGH7.5same product

Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ...

CVE-2023-2062MEDIUM6.2same product

Missing Password Field Masking vulnerability in Mitsubishi Electric Corporation EtherNet/IP configuration tool...

CVE-2023-2063MEDIUM6.3same product

Unrestricted Upload of File with Dangerous Type vulnerability in FTP function on Mitsubishi Electric Corporati...