Authentication Bypass Vulnerability in MELSEC WS Series Ethernet Interface Module
CVE-2023-1618

7.5HIGH

What is CVE-2023-1618?

An active debug code vulnerability in Mitsubishi Electric Corporation's MELSEC WS Series, specifically the WS0-GETH00200 module with serial numbers 2310 and prior, allows an unauthenticated remote attacker to bypass authentication. This vulnerability exploits a hidden telnet function, which is enabled by default upon factory shipment. By accessing the module through telnet, an attacker can gain unauthorized login access, potentially leading to the ability to reset the module and manipulate its configuration or firmware under certain conditions.

Affected Version(s)

MELSEC WS Series WS0-GETH00200 Serial number 2310 **** and prior

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.