Authentication Bypass Vulnerability in MELSEC WS Series Ethernet Interface Module
CVE-2023-1618
7.5HIGH
Key Information:
- Vendor
- CVE Published:
- 19 May 2023
What is CVE-2023-1618?
An active debug code vulnerability in Mitsubishi Electric Corporation's MELSEC WS Series, specifically the WS0-GETH00200 module with serial numbers 2310 and prior, allows an unauthenticated remote attacker to bypass authentication. This vulnerability exploits a hidden telnet function, which is enabled by default upon factory shipment. By accessing the module through telnet, an attacker can gain unauthorized login access, potentially leading to the ability to reset the module and manipulate its configuration or firmware under certain conditions.
Affected Version(s)
MELSEC WS Series WS0-GETH00200 Serial number 2310 **** and prior