7.5
CWE
522 256
Advisory Published
Updated

CVE-2023-0457: Information Disclosure Vulnerability in MELSEC Series

First published: Fri Mar 03 2023(Updated: )

Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into FTP server or Web server.

Credit: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp

Affected SoftwareAffected VersionHow to fix
Mitsubishielectric Fx5uc-32mr\/ds-ts Firmware
Mitsubishielectric Fx5uc-32mr\/ds-ts
Mitsubishielectric Fx5uc-32mt\/d Firmware
Mitsubishielectric Fx5uc-32mt\/d
Mitsubishielectric Fx5uc-32mt\/dss Firmware
Mitsubishielectric Fx5uc-32mt\/dss
Mitsubishielectric Fx5uc-32mt\/dss-ts Firmware
Mitsubishielectric Fx5uc-32mt\/dss-ts
Mitsubishielectric Fx5uc-32mt\/ds-ts Firmware
Mitsubishielectric Fx5uc-32mt\/ds-ts
Mitsubishielectric Fx5uc-64mt\/d Firmware
Mitsubishielectric Fx5uc-64mt\/d
Mitsubishielectric Fx5uc-64mt\/dss Firmware
Mitsubishielectric Fx5uc-64mt\/dss
Mitsubishielectric Fx5uc-96mt\/d Firmware
Mitsubishielectric Fx5uc-96mt\/d
Mitsubishielectric Fx5uc-96mt\/dss Firmware
Mitsubishielectric Fx5uc-96mt\/dss
Mitsubishielectric Fx5uj-24mr\/es Firmware
Mitsubishielectric Fx5uj-24mr\/es
Mitsubishielectric Fx5uj-24mr\/es-a Firmware
Mitsubishielectric Fx5uj-24mr\/es-a
Mitsubishielectric Fx5uj-24mt\/es Firmware
Mitsubishielectric Fx5uj-24mt\/es
Mitsubishielectric Fx5uj-24mt\/es-a Firmware
Mitsubishielectric Fx5uj-24mt\/es-a
Mitsubishielectric Fx5uj-24mt\/ess Firmware
Mitsubishielectric Fx5uj-24mt\/ess
Mitsubishielectric Fx5uj-40mr\/es Firmware
Mitsubishielectric Fx5uj-40mr\/es
Mitsubishielectric Fx5uj-40mr\/es-a Firmware
Mitsubishielectric Fx5uj-40mr\/es-a
Mitsubishielectric Fx5uj-40mt\/es Firmware
Mitsubishielectric Fx5uj-40mt\/es
Mitsubishielectric Fx5uj-40mt\/es-a Firmware
Mitsubishielectric Fx5uj-40mt\/es-a
Mitsubishielectric Fx5uj-40mt\/ess Firmware
Mitsubishielectric Fx5uj-40mt\/ess
Mitsubishielectric Fx5uj-60mr\/es Firmware
Mitsubishielectric Fx5uj-60mr\/es
Mitsubishielectric Fx5uj-60mr\/es-a Firmware
Mitsubishielectric Fx5uj-60mr\/es-a
Mitsubishielectric Fx5uj-60mt\/es Firmware
Mitsubishielectric Fx5uj-60mt\/es
Mitsubishielectric Fx5uj-60mt\/es-a Firmware
Mitsubishielectric Fx5uj-60mt\/es-a
Mitsubishielectric Fx5uj-60mt\/ess Firmware
Mitsubishielectric Fx5uj-60mt\/ess
Mitsubishielectric Fx5s-30mr\/es Firmware
Mitsubishielectric Fx5s-30mr\/es
Mitsubishielectric Fx5s-30mt\/es Firmware
Mitsubishielectric Fx5s-30mt\/es
Mitsubishielectric Fx5s-30mt\/ess Firmware
Mitsubishielectric Fx5s-30mt\/ess
Mitsubishielectric Fx5s-40mr\/es Firmware
Mitsubishielectric Fx5s-40mr\/es
Mitsubishielectric Fx5s-40mt\/es Firmware
Mitsubishielectric Fx5s-40mt\/es
Mitsubishielectric Fx5s-40mt\/ess Firmware
Mitsubishielectric Fx5s-40mt\/ess
Mitsubishielectric Fx5s-60mr\/es Firmware
Mitsubishielectric Fx5s-60mr\/es
Mitsubishielectric Fx5s-60mt\/es Firmware
Mitsubishielectric Fx5s-60mt\/es
Mitsubishielectric Fx5s-60mt\/ess Firmware
Mitsubishielectric Fx5s-60mt\/ess
Mitsubishielectric Fx5s-80mr\/es Firmware
Mitsubishielectric Fx5s-80mr\/es
Mitsubishielectric Fx5s-80mt\/es Firmware
Mitsubishielectric Fx5s-80mt\/es
Mitsubishielectric Fx5s-80mt\/ess Firmware
Mitsubishielectric Fx5s-80mt\/ess
Mitsubishielectric Fx5-enet Firmware
Mitsubishielectric Fx5-enet
Mitsubishielectric Fx5-enet\/ip Firmware
Mitsubishielectric Fx5-enet\/ip
Mitsubishi Electric MELSEC iQ-F FX5U(C) CPU modules: All models, all versions
Mitsubishi Electric MELSEC iQ-F FX5UJ CPU modules: All models, all versions
Mitsubishi Electric MELSEC iQ-F FX5S CPU modules: All models, all versions
Mitsubishi Electric MELSEC iQ-F FX5-ENET
Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP
Mitsubishi Electric MELSEC iQ-R R00/01/02CPU
Mitsubishi Electric MELSEC iQ-R R04/08/16/32/120(EN)CPU
Mitsubishi Electric MELSEC iQ-R R08/16/32/120SFCPU
Mitsubishi Electric MELSEC iQ-R R08/16/32/120PCPU
Mitsubishi Electric MELSEC iQ-R R08/16/32/120PSFCPU
Mitsubishi Electric MELSEC iQ-R RJ71EN71
Mitsubishi Electric MELSEC iQ-R R12CCPU-V
Mitsubishi Electric MELSEC-Q Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU
Mitsubishi Electric MELSEC-Q Q03/04/06/13/26UDVCPU
Mitsubishi Electric MELSEC-Q Q04/06/13/26UDPVCPU
Mitsubishi Electric MELSEC-Q QJ71E71-100
Mitsubishi Electric MELSEC-L L02/06/26CPU(-P), L26CPU-(P)BT
Mitsubishi Electric MELSEC-L LJ71E71-100

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Parent vulnerabilities

(Appears in the following advisories)

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203