Authentication Bypass Vulnerability in MELSEC WS Series Ethernet Interface Module
CVE-2023-1618
Key Information:
- Vendor
- CVE Published:
- 19 May 2023
What is CVE-2023-1618?
An active debug code vulnerability in Mitsubishi Electric Corporation's MELSEC WS Series, specifically the WS0-GETH00200 module with serial numbers 2310 and prior, allows an unauthenticated remote attacker to bypass authentication. This vulnerability exploits a hidden telnet function, which is enabled by default upon factory shipment. By accessing the module through telnet, an attacker can gain unauthorized login access, potentially leading to the ability to reset the module and manipulate its configuration or firmware under certain conditions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MELSEC WS Series WS0-GETH00200 Serial number 2310 **** and prior
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
