Authentication bypass vulnerability in MELSEC iQ-R Series / iQ-F Series EtherNet/IP Modules
CVE-2023-2060

7.5HIGH

Summary

A vulnerability exists in the FTP function of Mitsubishi Electric's MELSEC iQ-R Series and iQ-F Series EtherNet/IP modules that allows remote unauthenticated attackers to gain access through weak password requirements. Utilizing techniques such as dictionary attacks or password sniffing, attackers can exploit this weakness to compromise the integrity of the modules, posing significant security threats to the connected systems.

Affected Version(s)

MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP all versions

MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 all versions

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.