CVE-2023-0457

Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into FTP server or Web server.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uc-32mr\/ds-ts_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uc-32mr\/ds-ts:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uc-32mt\/d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uc-32mt\/d:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uc-32mt\/dss_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uc-32mt\/dss:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uc-32mt\/dss-ts_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uc-32mt\/dss-ts:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uc-32mt\/ds-ts_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uc-32mt\/ds-ts:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uc-64mt\/d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uc-64mt\/d:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uc-64mt\/dss_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uc-64mt\/dss:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uc-96mt\/d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uc-96mt\/d:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uc-96mt\/dss_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uc-96mt\/dss:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uj-24mr\/es_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uj-24mr\/es:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uj-24mr\/es-a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uj-24mr\/es-a:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uj-24mt\/es_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uj-24mt\/es:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uj-24mt\/es-a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uj-24mt\/es-a:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uj-24mt\/ess_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uj-24mt\/ess:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uj-40mr\/es_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uj-40mr\/es:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uj-40mr\/es-a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uj-40mr\/es-a:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uj-40mt\/es_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uj-40mt\/es:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uj-40mt\/es-a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uj-40mt\/es-a:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uj-40mt\/ess_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uj-40mt\/ess:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uj-60mr\/es_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uj-60mr\/es:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uj-60mr\/es-a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uj-60mr\/es-a:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uj-60mt\/es_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uj-60mt\/es:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uj-60mt\/es-a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uj-60mt\/es-a:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5uj-60mt\/ess_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5uj-60mt\/ess:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5s-30mr\/es_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5s-30mr\/es:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5s-30mt\/es_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5s-30mt\/es:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5s-30mt\/ess_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5s-30mt\/ess:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5s-40mr\/es_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5s-40mr\/es:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5s-40mt\/es_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5s-40mt\/es:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5s-40mt\/ess_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5s-40mt\/ess:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5s-60mr\/es_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5s-60mr\/es:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5s-60mt\/es_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5s-60mt\/es:-:*:*:*:*:*:*:*

Configuration 33 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5s-60mt\/ess_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5s-60mt\/ess:-:*:*:*:*:*:*:*

Configuration 34 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5s-80mr\/es_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5s-80mr\/es:-:*:*:*:*:*:*:*

Configuration 35 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5s-80mt\/es_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5s-80mt\/es:-:*:*:*:*:*:*:*

Configuration 36 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5s-80mt\/ess_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5s-80mt\/ess:-:*:*:*:*:*:*:*

Configuration 37 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5-enet_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5-enet:-:*:*:*:*:*:*:*

Configuration 38 (hide)

AND
cpe:2.3:o:mitsubishielectric:fx5-enet\/ip_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:fx5-enet\/ip:-:*:*:*:*:*:*:*

History

21 Jun 2023, 05:15

Type Values Removed Values Added
Summary Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U(C) CPU modules all models all versions, FX5UJ CPU modules all models all versions, FX5S CPU modules all models all versions, FX5-ENET all versions and FX5-ENET/IP all versions allows a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into FTP server or Web server. Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into FTP server or Web server.

Information

Published : 2023-03-03 05:15

Updated : 2024-02-28 19:51


NVD link : CVE-2023-0457

Mitre link : CVE-2023-0457

CVE.ORG link : CVE-2023-0457


JSON object : View

Products Affected

mitsubishielectric

  • fx5uj-60mr\/es
  • fx5uj-24mt\/es
  • fx5-enet_firmware
  • fx5uc-96mt\/dss_firmware
  • fx5s-80mr\/es_firmware
  • fx5uc-64mt\/dss_firmware
  • fx5uj-60mt\/ess
  • fx5uj-24mr\/es
  • fx5s-80mt\/ess_firmware
  • fx5s-30mt\/es
  • fx5s-30mt\/ess_firmware
  • fx5uj-60mr\/es-a_firmware
  • fx5s-60mt\/es
  • fx5s-30mt\/ess
  • fx5s-30mt\/es_firmware
  • fx5uc-96mt\/d_firmware
  • fx5uj-40mr\/es
  • fx5uc-32mt\/dss_firmware
  • fx5uc-32mt\/dss-ts
  • fx5s-40mt\/ess_firmware
  • fx5s-60mt\/es_firmware
  • fx5uc-32mt\/dss-ts_firmware
  • fx5uj-24mr\/es-a
  • fx5s-40mr\/es_firmware
  • fx5uc-96mt\/d
  • fx5uc-64mt\/d
  • fx5uj-60mt\/es-a_firmware
  • fx5s-40mt\/ess
  • fx5-enet\/ip_firmware
  • fx5uj-40mt\/ess
  • fx5uj-24mr\/es_firmware
  • fx5s-60mt\/ess_firmware
  • fx5uj-40mt\/es_firmware
  • fx5uj-40mr\/es_firmware
  • fx5s-30mr\/es
  • fx5s-60mr\/es
  • fx5s-80mt\/es
  • fx5uj-24mt\/es-a_firmware
  • fx5uc-32mr\/ds-ts
  • fx5uj-40mt\/es
  • fx5s-40mt\/es
  • fx5uj-24mt\/ess_firmware
  • fx5uc-32mt\/ds-ts
  • fx5uc-32mt\/ds-ts_firmware
  • fx5s-40mt\/es_firmware
  • fx5s-30mr\/es_firmware
  • fx5s-80mt\/ess
  • fx5uc-32mt\/d
  • fx5uj-40mt\/es-a_firmware
  • fx5uc-64mt\/d_firmware
  • fx5uj-40mt\/es-a
  • fx5uj-60mr\/es_firmware
  • fx5uj-40mr\/es-a_firmware
  • fx5-enet\/ip
  • fx5uj-24mr\/es-a_firmware
  • fx5uc-32mt\/dss
  • fx5uj-24mt\/es_firmware
  • fx5uj-60mt\/es_firmware
  • fx5s-40mr\/es
  • fx5uj-24mt\/es-a
  • fx5uj-60mt\/es
  • fx5uj-60mt\/ess_firmware
  • fx5uc-96mt\/dss
  • fx5s-60mt\/ess
  • fx5uj-24mt\/ess
  • fx5s-80mt\/es_firmware
  • fx5uc-32mt\/d_firmware
  • fx5uj-60mr\/es-a
  • fx5uj-40mt\/ess_firmware
  • fx5uj-60mt\/es-a
  • fx5uc-64mt\/dss
  • fx5s-80mr\/es
  • fx5uc-32mr\/ds-ts_firmware
  • fx5-enet
  • fx5uj-40mr\/es-a
  • fx5s-60mr\/es_firmware
CWE
CWE-522

Insufficiently Protected Credentials

CWE-256

Plaintext Storage of a Password