CVE-2023-4562: Information Disclosure, Information Tampering and Authentication Bypass Vulnerability in MELSEC-F Series main module
Improper Authentication vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules allows a remote unauthenticated attacker to obtain sequence programs from the product or write malicious sequence programs or improper data in the product without authentication by sending illegitimate messages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-4562?
CVE-2023-4562 is classified as a critical vulnerability due to its potential impact on unauthorized access to control systems.
How do I fix CVE-2023-4562?
To mitigate CVE-2023-4562, users should apply the latest firmware updates provided by Mitsubishi Electric for affected devices.
What types of devices are affected by CVE-2023-4562?
CVE-2023-4562 affects various models within the Mitsubishi Electric MELSEC-F Series, including specific versions of FX3G and FX3U controllers.
Can CVE-2023-4562 be exploited remotely?
Yes, CVE-2023-4562 allows an unauthenticated remote attacker to exploit the vulnerability and gain unauthorized access.
What could an attacker achieve by exploiting CVE-2023-4562?
Exploitation of CVE-2023-4562 could allow an attacker to access and modify critical sequence programs and data within the affected systems.