CVE-2023-0457

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
03/03/2023
Last modified:
21/06/2023

Description

Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into FTP server or Web server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:mitsubishielectric:fx5uc-32mr\/ds-ts_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uc-32mr\/ds-ts:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:fx5uc-32mt\/d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uc-32mt\/d:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:fx5uc-32mt\/dss_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uc-32mt\/dss:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:fx5uc-32mt\/dss-ts_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uc-32mt\/dss-ts:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:fx5uc-32mt\/ds-ts_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uc-32mt\/ds-ts:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:fx5uc-64mt\/d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uc-64mt\/d:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:fx5uc-64mt\/dss_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uc-64mt\/dss:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:fx5uc-96mt\/d_firmware:*:*:*:*:*:*:*:*