7.5
CWE
522 256
Advisory Published
Updated

CVE-2023-0457: Information Disclosure Vulnerability in MELSEC Series

First published: Fri Mar 03 2023(Updated: )

Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into FTP server or Web server.

Credit: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp

Affected SoftwareAffected VersionHow to fix
Mitsubishielectric Fx5uc-32mr/ds-ts Firmware
Mitsubishi Electric FX5UC-32MR/DS-TS
Mitsubishi Electric FX5UC-32MT/D Firmware
Mitsubishielectric Fx5uc-32mt/d
Mitsubishi Electric FX5UC-32MT/DSS Firmware
Mitsubishi Electric FX5UC-32MT/DSS
Mitsubishi Electric FX5UC-32MT/DSS-TS Firmware
Mitsubishi Electric FX5UC-32MT/DSS-TS
Mitsubishi Electric FX5UC-32MT/DS-TS Firmware
Mitsubishi Electric FX5UC-32MT/DS-TS
Mitsubishi Electric FX5UC-64MT/D Firmware
Mitsubishi Electric FX5UC-64MT/D
Mitsubishi Electric FX5UC-64MT/DSS Firmware
Mitsubishielectric Fx5uc-64mt/dss
Mitsubishi Electric FX5UC-96MT/D Firmware
Mitsubishielectric Fx5uc-96mt/d
Mitsubishi Electric FX5UC-96MT/DSS Firmware
Mitsubishi Electric FX5UC-96MT/DSS
Mitsubishielectric Fx5uj-24mr/es Firmware
Mitsubishi Electric FX5UJ-24MR/ES
Mitsubishi Electric FX5UJ-24MR/ES-A Firmware
Mitsubishielectric Fx5uj-24mr/es-a
Mitsubishi Electric FX5UJ-24MT/ES Firmware
Mitsubishi Electric FX5UJ-24MT/ES
Mitsubishielectric Fx5uj-24mt/es-a Firmware
Mitsubishi Electric FX5UJ-24MT/ES-A
Mitsubishi Electric FX5UJ-24MT/ESS Firmware
Mitsubishielectric FX5UJ-24MT/ESS
Mitsubishi Electric FX5UJ-40MR/ES Firmware
Mitsubishi Electric FX5UJ-40MR/ES
Mitsubishielectric Fx5uj-40mr/es-a Firmware
Mitsubishi Electric FX5UJ-40MR/ES-A
Mitsubishi Electric FX5UJ-40MT/ES Firmware
Mitsubishi Electric FX5UJ-40MT/ES
Mitsubishi Electric FX5UJ-40MT/ES-A Firmware
Mitsubishi Electric FX5UJ-40MT/ES-A
Mitsubishielectric Fx5uj-40mt/ess Firmware
Mitsubishi Electric FX5UJ-40MT/ESS
Mitsubishi Electric FX5UJ-60MR/ES Firmware
Mitsubishi Electric FX5UJ-60MR/ES
Mitsubishi Electric FX5UJ-60MR/ES-A Firmware
Mitsubishielectric Fx5uj-60mr/es-a
Mitsubishielectric Fx5uj-60mt/es Firmware
Mitsubishielectric Fx5uj-60mt/es
Mitsubishi Electric FX5UJ-60MT/ES-A Firmware
Mitsubishi Electric FX5UJ-60MT/ES-A
Mitsubishi Electric FX5UJ-60MT/ESS Firmware
Mitsubishi Electric FX5UJ-60MT/ESS
Mitsubishielectric Fx5s-30mr/es Firmware
Mitsubishielectric Fx5s-30mr/es
Mitsubishielectric Fx5s-30mt/es Firmware
Mitsubishi Electric FX5S-30MT/ES
Mitsubishi Electric FX5S-30MT/ESS Firmware
Mitsubishi Electric FX5S-30MT/ESS
Mitsubishi Electric FX5S-40MR/ES Firmware
Mitsubishi Electric FX5S-40MR/ES
Mitsubishi Electric FX5S-40MT/ES Firmware
Mitsubishi Electric FX5S-40MT/ES
Mitsubishielectric Fx5s-40mt/ess Firmware
Mitsubishi Electric FX5S-40MT/ESS
Mitsubishi Electric FX5S-60MR/ES Firmware
Mitsubishi Electric FX5S-60MR/ES
Mitsubishi Electric FX5S-60MT/ES Firmware
Mitsubishi Electric FX5S-60MT/ES
Mitsubishi Electric FX5S-60MT/ESS Firmware
Mitsubishi Electric FX5S-60MT/ESS
Mitsubishielectric Fx5s-80mr/es Firmware
Mitsubishi Electric FX5S-80MR/ES
Mitsubishi Electric FX5S-80MT/ES Firmware
Mitsubishi Electric FX5S-80MT/ES
Mitsubishi Electric FX5S-80MT/ESS Firmware
Mitsubishi Electric FX5S-80MT/ESS
Mitsubishi Electric FX5_ENET Firmware
Mitsubishi Electric FX5-ENET
Mitsubishi Electric FX5-ENET/IP Firmware
Mitsubishi Electric FX5-ENET/IP Firmware
Mitsubishi Electric MELSEC iQ-F FX5UJ CPU modules
Mitsubishi Electric MELSEC iQ-F FX5UJ CPU modules
Mitsubishi Electric MELSEC iQ-F FX5S CPU
Mitsubishi Electric MELSEC iQ-F Series Ethernet module FX5-ENET
Mitsubishi Electric FX5-ENET/IP
Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU
Mitsubishi Electric MELSEC iQ-R Series R04/08/16/32/120(EN)CPU
Mitsubishi Electric R08/16/32/120SFCPU
Mitsubishi Electric MELSEC iQ-R series CPU module R08/16/32/120PCPU
Mitsubishi Electric MELSEC iQ-R Series SIL2 Process CPU R120PSFCPU
Mitsubishi Electric MELSEC iQ-R Ethernet Interface Module RJ71EN71
Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V CPU Firmware
Mitsubishi Electric MELSEC-Q Series
Mitsubishi Electric MELSEC-Q Series
Mitsubishi Electric MELSEC-Q Series Q04/06/13/26UDPVCPU
Mitsubishi Melsec QJ71E71-100 Firmware
Mitsubishi Melsec L26CPU-(P)BT
Mitsubishi Melsec Lj71e71-100 Firmware

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Parent vulnerabilities

(Appears in the following advisories)

Frequently Asked Questions

  • What is the severity of CVE-2023-0457?

    CVE-2023-0457 has been classified as a significant security vulnerability due to the potential for unauthorized access to plaintext credentials.

  • How do I fix CVE-2023-0457?

    To mitigate CVE-2023-0457, ensure that you upgrade to the latest firmware version provided by Mitsubishi Electric.

  • Which Mitsubishi Electric products are affected by CVE-2023-0457?

    CVE-2023-0457 affects various models from the MELSEC iQ-F, iQ-R, Q, and L series, including the FX5U, FX5UJ, and others listed in the advisory.

  • What can an attacker do if they exploit CVE-2023-0457?

    If exploited, an attacker can potentially access and disclose plaintext credentials stored in project files and gain unauthorized login access to FTP servers.

  • Is CVE-2023-0457 a remote vulnerability?

    Yes, CVE-2023-0457 allows a remote unauthenticated attacker to exploit the vulnerability without physical access to the affected systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203