First published: Fri Mar 03 2023(Updated: )
Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into FTP server or Web server.
Credit: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishielectric Fx5uc-32mr/ds-ts Firmware | ||
Mitsubishi Electric FX5UC-32MR/DS-TS | ||
Mitsubishi Electric FX5UC-32MT/D Firmware | ||
Mitsubishielectric Fx5uc-32mt/d | ||
Mitsubishi Electric FX5UC-32MT/DSS Firmware | ||
Mitsubishi Electric FX5UC-32MT/DSS | ||
Mitsubishi Electric FX5UC-32MT/DSS-TS Firmware | ||
Mitsubishi Electric FX5UC-32MT/DSS-TS | ||
Mitsubishi Electric FX5UC-32MT/DS-TS Firmware | ||
Mitsubishi Electric FX5UC-32MT/DS-TS | ||
Mitsubishi Electric FX5UC-64MT/D Firmware | ||
Mitsubishi Electric FX5UC-64MT/D | ||
Mitsubishi Electric FX5UC-64MT/DSS Firmware | ||
Mitsubishielectric Fx5uc-64mt/dss | ||
Mitsubishi Electric FX5UC-96MT/D Firmware | ||
Mitsubishielectric Fx5uc-96mt/d | ||
Mitsubishi Electric FX5UC-96MT/DSS Firmware | ||
Mitsubishi Electric FX5UC-96MT/DSS | ||
Mitsubishielectric Fx5uj-24mr/es Firmware | ||
Mitsubishi Electric FX5UJ-24MR/ES | ||
Mitsubishi Electric FX5UJ-24MR/ES-A Firmware | ||
Mitsubishielectric Fx5uj-24mr/es-a | ||
Mitsubishi Electric FX5UJ-24MT/ES Firmware | ||
Mitsubishi Electric FX5UJ-24MT/ES | ||
Mitsubishielectric Fx5uj-24mt/es-a Firmware | ||
Mitsubishi Electric FX5UJ-24MT/ES-A | ||
Mitsubishi Electric FX5UJ-24MT/ESS Firmware | ||
Mitsubishielectric FX5UJ-24MT/ESS | ||
Mitsubishi Electric FX5UJ-40MR/ES Firmware | ||
Mitsubishi Electric FX5UJ-40MR/ES | ||
Mitsubishielectric Fx5uj-40mr/es-a Firmware | ||
Mitsubishi Electric FX5UJ-40MR/ES-A | ||
Mitsubishi Electric FX5UJ-40MT/ES Firmware | ||
Mitsubishi Electric FX5UJ-40MT/ES | ||
Mitsubishi Electric FX5UJ-40MT/ES-A Firmware | ||
Mitsubishi Electric FX5UJ-40MT/ES-A | ||
Mitsubishielectric Fx5uj-40mt/ess Firmware | ||
Mitsubishi Electric FX5UJ-40MT/ESS | ||
Mitsubishi Electric FX5UJ-60MR/ES Firmware | ||
Mitsubishi Electric FX5UJ-60MR/ES | ||
Mitsubishi Electric FX5UJ-60MR/ES-A Firmware | ||
Mitsubishielectric Fx5uj-60mr/es-a | ||
Mitsubishielectric Fx5uj-60mt/es Firmware | ||
Mitsubishielectric Fx5uj-60mt/es | ||
Mitsubishi Electric FX5UJ-60MT/ES-A Firmware | ||
Mitsubishi Electric FX5UJ-60MT/ES-A | ||
Mitsubishi Electric FX5UJ-60MT/ESS Firmware | ||
Mitsubishi Electric FX5UJ-60MT/ESS | ||
Mitsubishielectric Fx5s-30mr/es Firmware | ||
Mitsubishielectric Fx5s-30mr/es | ||
Mitsubishielectric Fx5s-30mt/es Firmware | ||
Mitsubishi Electric FX5S-30MT/ES | ||
Mitsubishi Electric FX5S-30MT/ESS Firmware | ||
Mitsubishi Electric FX5S-30MT/ESS | ||
Mitsubishi Electric FX5S-40MR/ES Firmware | ||
Mitsubishi Electric FX5S-40MR/ES | ||
Mitsubishi Electric FX5S-40MT/ES Firmware | ||
Mitsubishi Electric FX5S-40MT/ES | ||
Mitsubishielectric Fx5s-40mt/ess Firmware | ||
Mitsubishi Electric FX5S-40MT/ESS | ||
Mitsubishi Electric FX5S-60MR/ES Firmware | ||
Mitsubishi Electric FX5S-60MR/ES | ||
Mitsubishi Electric FX5S-60MT/ES Firmware | ||
Mitsubishi Electric FX5S-60MT/ES | ||
Mitsubishi Electric FX5S-60MT/ESS Firmware | ||
Mitsubishi Electric FX5S-60MT/ESS | ||
Mitsubishielectric Fx5s-80mr/es Firmware | ||
Mitsubishi Electric FX5S-80MR/ES | ||
Mitsubishi Electric FX5S-80MT/ES Firmware | ||
Mitsubishi Electric FX5S-80MT/ES | ||
Mitsubishi Electric FX5S-80MT/ESS Firmware | ||
Mitsubishi Electric FX5S-80MT/ESS | ||
Mitsubishi Electric FX5_ENET Firmware | ||
Mitsubishi Electric FX5-ENET | ||
Mitsubishi Electric FX5-ENET/IP Firmware | ||
Mitsubishi Electric FX5-ENET/IP Firmware | ||
Mitsubishi Electric MELSEC iQ-F FX5UJ CPU modules | ||
Mitsubishi Electric MELSEC iQ-F FX5UJ CPU modules | ||
Mitsubishi Electric MELSEC iQ-F FX5S CPU | ||
Mitsubishi Electric MELSEC iQ-F Series Ethernet module FX5-ENET | ||
Mitsubishi Electric FX5-ENET/IP | ||
Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU | ||
Mitsubishi Electric MELSEC iQ-R Series R04/08/16/32/120(EN)CPU | ||
Mitsubishi Electric R08/16/32/120SFCPU | ||
Mitsubishi Electric MELSEC iQ-R series CPU module R08/16/32/120PCPU | ||
Mitsubishi Electric MELSEC iQ-R Series SIL2 Process CPU R120PSFCPU | ||
Mitsubishi Electric MELSEC iQ-R Ethernet Interface Module RJ71EN71 | ||
Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V CPU Firmware | ||
Mitsubishi Electric MELSEC-Q Series | ||
Mitsubishi Electric MELSEC-Q Series | ||
Mitsubishi Electric MELSEC-Q Series Q04/06/13/26UDPVCPU | ||
Mitsubishi Melsec QJ71E71-100 Firmware | ||
Mitsubishi Melsec L26CPU-(P)BT | ||
Mitsubishi Melsec Lj71e71-100 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0457 has been classified as a significant security vulnerability due to the potential for unauthorized access to plaintext credentials.
To mitigate CVE-2023-0457, ensure that you upgrade to the latest firmware version provided by Mitsubishi Electric.
CVE-2023-0457 affects various models from the MELSEC iQ-F, iQ-R, Q, and L series, including the FX5U, FX5UJ, and others listed in the advisory.
If exploited, an attacker can potentially access and disclose plaintext credentials stored in project files and gain unauthorized login access to FTP servers.
Yes, CVE-2023-0457 allows a remote unauthenticated attacker to exploit the vulnerability without physical access to the affected systems.