CVE-2023-0457

HIGHCVSS 7.5/10EPSS 1.17%

Last modified

CVE-2023-0457 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into FTP server or Web server.. EPSS estimates a 1.17% chance of exploitation in the next 30 days.

Description

Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into FTP server or Web server.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
1.17%

63.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
MitsubishielectricFx5uc-32mr\/Ds-Ts FirmwareAll versions
MitsubishielectricFx5uc-32mt\/D FirmwareAll versions
MitsubishielectricFx5uc-32mt\/Dss FirmwareAll versions
MitsubishielectricFx5uc-32mt\/Dss-Ts FirmwareAll versions
MitsubishielectricFx5uc-32mt\/Ds-Ts FirmwareAll versions
MitsubishielectricFx5uc-64mt\/D FirmwareAll versions
MitsubishielectricFx5uc-64mt\/Dss FirmwareAll versions
MitsubishielectricFx5uc-96mt\/D FirmwareAll versions
MitsubishielectricFx5uc-96mt\/Dss FirmwareAll versions
MitsubishielectricFx5uj-24mr\/Es FirmwareAll versions
MitsubishielectricFx5uj-24mr\/Es-A FirmwareAll versions
MitsubishielectricFx5uj-24mt\/Es FirmwareAll versions
MitsubishielectricFx5uj-24mt\/Es-A FirmwareAll versions
MitsubishielectricFx5uj-24mt\/Ess FirmwareAll versions
MitsubishielectricFx5uj-40mr\/Es FirmwareAll versions
MitsubishielectricFx5uj-40mr\/Es-A FirmwareAll versions
MitsubishielectricFx5uj-40mt\/Es FirmwareAll versions
MitsubishielectricFx5uj-40mt\/Es-A FirmwareAll versions
MitsubishielectricFx5uj-40mt\/Ess FirmwareAll versions
MitsubishielectricFx5uj-60mr\/Es FirmwareAll versions
MitsubishielectricFx5uj-60mr\/Es-A FirmwareAll versions
MitsubishielectricFx5uj-60mt\/Es FirmwareAll versions
MitsubishielectricFx5uj-60mt\/Es-A FirmwareAll versions
MitsubishielectricFx5uj-60mt\/Ess FirmwareAll versions
MitsubishielectricFx5s-30mr\/Es FirmwareAll versions
MitsubishielectricFx5s-30mt\/Es FirmwareAll versions
MitsubishielectricFx5s-30mt\/Ess FirmwareAll versions
MitsubishielectricFx5s-40mr\/Es FirmwareAll versions
MitsubishielectricFx5s-40mt\/Es FirmwareAll versions
MitsubishielectricFx5s-40mt\/Ess FirmwareAll versions
MitsubishielectricFx5s-60mr\/Es FirmwareAll versions
MitsubishielectricFx5s-60mt\/Es FirmwareAll versions
MitsubishielectricFx5s-60mt\/Ess FirmwareAll versions
MitsubishielectricFx5s-80mr\/Es FirmwareAll versions
MitsubishielectricFx5s-80mt\/Es FirmwareAll versions
MitsubishielectricFx5s-80mt\/Ess FirmwareAll versions
MitsubishielectricFx5-Enet FirmwareAll versions
MitsubishielectricFx5-Enet\/Ip FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-0457?
Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into FTP server or Web server.
How severe is CVE-2023-0457?
CVE-2023-0457 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 1.17% probability of exploitation in the next 30 days.
How do I fix CVE-2023-0457?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-0457?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST