Lucene search

K
nvd[email protected]NVD:CVE-2023-2062
HistoryJun 02, 2023 - 5:15 a.m.

CVE-2023-2062

2023-06-0205:15:10
CWE-549
CWE-668
web.nvd.nist.gov
1
cve-2023-2062
missing password field
remote unauthenticated attacker
melsec iq-r series
melsec iq-f series
ethernet/ip
authentication bypass
access control
ftp

6.2 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

6.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.1%

Missing Password Field Masking vulnerability in Mitsubishi Electric Corporation EtherNet/IP configuration tools SW1DNN-EIPCT-BD and SW1DNN-EIPCTFX5-BD allows a remote unauthenticated attacker to know the password for MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP. This vulnerability results in authentication bypass vulnerability, which allows the attacker to access MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP via FTP.

Affected configurations

NVD
Node
mitsubishielectricfx5-enet\/ip_firmwareMatch-
AND
mitsubishielectricfx5-enet\/ipMatch-
Node
mitsubishielectricsw1dnn-eipct-bd_firmwareMatch-
AND
mitsubishielectricsw1dnn-eipct-bdMatch-
Node
mitsubishielectricrj71eip91_firmwareMatch-
AND
mitsubishielectricrj71eip91Match-
Node
mitsubishielectricsw1dnn-eipctfx5-bd_firmwareMatch-
AND
mitsubishielectricsw1dnn-eipctfx5-bdMatch-

6.2 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

6.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.1%

Related for NVD:CVE-2023-2062