CVE-2023-2062
Published: Jun 2, 2023
Modified: Mar 5, 2025
CVSS v3.1
6.2
Description
Missing Password Field Masking vulnerability in Mitsubishi Electric Corporation EtherNet/IP configuration tools SW1DNN-EIPCT-BD and SW1DNN-EIPCTFX5-BD allows a remote unauthenticated attacker to know the password for MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP. This vulnerability results in authentication bypass vulnerability, which allows the attacker to access MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP via FTP.
| Vendor | Product | Versions |
|---|---|---|
Mitsubishi Electric Corporation | EtherNet/IP Configuration tool for RJ71EIP91 SW1DNN-EIPCT-BD | affected Software version "1.01B" and prior |
Mitsubishi Electric Corporation | EtherNet/IP Configuration tool for FX5-ENET/IP SW1DNN-EIPCTFX5-BD | affected Software version "1.01B" and prior |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now