CVE-2023-2062: Information Disclosure vulnerability in EtherNet/IP Configuration tools
Missing Password Field Masking vulnerability in Mitsubishi Electric Corporation EtherNet/IP configuration tools SW1DNN-EIPCT-BD and SW1DNN-EIPCTFX5-BD allows a remote unauthenticated attacker to know the password for MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP. This vulnerability results in authentication bypass vulnerability, which allows the attacker to access MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP via FTP.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of the Missing Password Field Masking vulnerability in Mitsubishi Electric Corporation EtherNet/IP configuration tools?
The vulnerability ID is CVE-2023-2062.
What is the severity of CVE-2023-2062?
The severity of CVE-2023-2062 is medium.
Which software is affected by CVE-2023-2062?
The affected software are Mitsubishi Electric Corporation EtherNet/IP configuration tools SW1DNN-EIPCT-BD and SW1DNN-EIPCTFX5-BD.
How does the Missing Password Field Masking vulnerability work?
The vulnerability allows a remote unauthenticated attacker to know the password for MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP.
How to fix the Missing Password Field Masking vulnerability?
Apply the necessary patches or updates provided by Mitsubishi Electric Corporation.