Authentication bypass vulnerability in MELSEC iQ-R Series / iQ-F Series EtherNet/IP Modules
CVE-2023-2060
Key Information:
- Status
- Vendor
- CVE Published:
- 2 June 2023
What is CVE-2023-2060?
A vulnerability exists in the FTP function of Mitsubishi Electric's MELSEC iQ-R Series and iQ-F Series EtherNet/IP modules that allows remote unauthenticated attackers to gain access through weak password requirements. Utilizing techniques such as dictionary attacks or password sniffing, attackers can exploit this weakness to compromise the integrity of the modules, posing significant security threats to the connected systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP all versions
MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 all versions
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
