Vulnerabilities > Mitsubishielectric > Fx3U Enet Firmware

DATE CVE VULNERABILITY TITLE RISK
2023-10-13 CVE-2023-4562 Improper Authentication vulnerability in Mitsubishielectric products
Improper Authentication vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules allows a remote unauthenticated attacker to obtain sequence programs from the product or write malicious sequence programs or improper data in the product without authentication by sending illegitimate messages.
network
low complexity
mitsubishielectric CWE-287
critical
9.1
2022-01-14 CVE-2021-20612 Unspecified vulnerability in Mitsubishielectric products
Lack of administrator control over security vulnerability in MELSEC-F series FX3U-ENET Firmware version 1.14 and prior, FX3U-ENET-L Firmware version 1.14 and prior and FX3U-ENET-P502 Firmware version 1.14 and prior allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition in communication function of the product or other unspecified effects by sending specially crafted packets to an unnecessary opening of TCP port.
network
low complexity
mitsubishielectric
7.5
2022-01-14 CVE-2021-20613 Improper Initialization vulnerability in Mitsubishielectric products
Improper initialization vulnerability in MELSEC-F series FX3U-ENET Firmware version 1.16 and prior, FX3U-ENET-L Firmware version 1.16 and prior and FX3U-ENET-P502 Firmware version 1.16 and prior allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition in communication function of the product by sending specially crafted packets.
network
low complexity
mitsubishielectric CWE-665
7.8
2021-07-22 CVE-2021-20596 NULL Pointer Dereference vulnerability in Mitsubishielectric products
NULL Pointer Dereference in MELSEC-F Series FX3U-ENET firmware version 1.14 and prior, FX3U-ENET-L firmware version 1.14 and prior and FX3U-ENET-P502 firmware version 1.14 and prior allows a remote unauthenticated attacker to cause a DoS condition in communication by sending specially crafted packets.
network
low complexity
mitsubishielectric CWE-476
5.0
2020-10-05 CVE-2020-16226 Predictable Exact Value from Previous Values vulnerability in Mitsubishielectric products
Multiple Mitsubishi Electric products are vulnerable to impersonations of a legitimate device by a malicious actor, which may allow an attacker to remotely execute arbitrary commands.
network
low complexity
mitsubishielectric CWE-342
7.5