CVE-2023-2061: Authentication bypass vulnerability in MELSEC iQ-R Series / iQ-F Series EtherNet/IP Modules
Use of Hard-coded Password vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to obtain a hard-coded password and access to the module via FTP.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-2061?
CVE-2023-2061 is a vulnerability in the FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP.
How does CVE-2023-2061 affect Mitsubishi Electric Corporation?
CVE-2023-2061 allows a remote unauthenticated attacker to obtain a hard-coded password and access the module via FTP on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP.
What is the severity of CVE-2023-2061?
CVE-2023-2061 has a severity score of 7.5 (high).
How can I fix CVE-2023-2061?
To fix CVE-2023-2061, it is recommended to update the firmware of Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP.
Where can I find more information about CVE-2023-2061?
More information about CVE-2023-2061 can be found on the Mitsubishi Electric Corporation PSIRT website and the Japan Vulnerability Notes (JVN) website.