Vulnerabilities > Mitsubishielectric > High

DATE CVE VULNERABILITY TITLE RISK
2023-06-02 CVE-2023-2060 Weak Password Requirements vulnerability in Mitsubishielectric products
Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to access to the module via FTP by dictionary attack or password sniffing.
network
low complexity
mitsubishielectric CWE-521
7.5
2023-06-02 CVE-2023-2061 Use of Hard-coded Credentials vulnerability in Mitsubishielectric products
Use of Hard-coded Password vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to obtain a hard-coded password and access to the module via FTP.
network
low complexity
mitsubishielectric CWE-798
7.5
2023-06-02 CVE-2023-2063 Unrestricted Upload of File with Dangerous Type vulnerability in Mitsubishielectric products
Unrestricted Upload of File with Dangerous Type vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to cause information disclosure, tampering, deletion or destruction via file upload/download.
network
low complexity
mitsubishielectric CWE-434
7.3
2023-05-24 CVE-2023-1424 Classic Buffer Overflow vulnerability in Mitsubishielectric products
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules and MELSEC iQ-R Series CPU modules allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on a target product by sending specially crafted packets.
network
high complexity
mitsubishielectric CWE-120
8.1
2023-05-19 CVE-2023-1618 Insecure Default Initialization of Resource vulnerability in Mitsubishielectric Melsec Ws0-Geth00200 Firmware
Active Debug Code vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 Serial number 2310 **** and prior allows a remote unauthenticated attacker to bypass authentication and illegally log into the affected module by connecting to it via telnet which is hidden function and is enabled by default when shipped from the factory.
network
low complexity
mitsubishielectric CWE-1188
8.6
2023-03-03 CVE-2023-0457 Insufficiently Protected Credentials vulnerability in Mitsubishielectric products
Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into FTP server or Web server.
network
low complexity
mitsubishielectric CWE-522
7.5
2023-02-02 CVE-2022-40269 Authentication Bypass by Spoofing vulnerability in Mitsubishielectric Gt25 Firmware, Gt27 Firmware and GT Softgot2000
Authentication Bypass by Spoofing vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.14.000 to 01.47.000, Mitsubishi Electric Corporation GOT2000 Series GT25 model versions 01.14.000 to 01.47.000 and Mitsubishi Electric Corporation GT SoftGOT2000 versions 1.265B to 1.285X allows a remote unauthenticated attacker to disclose sensitive information from users' browsers or spoof legitimate users by abusing inappropriate HTML attributes.
network
low complexity
mitsubishielectric CWE-290
8.1
2023-02-02 CVE-2022-33323 Unspecified vulnerability in Mitsubishielectric products
Active Debug Code vulnerability in robot controller of Mitsubishi Electric Corporation industrial robot MELFA SD/SQ Series and MELFA F-Series allows a remote unauthenticated attacker to gain unauthorized access by authentication bypass through an unauthorized telnet login.
network
low complexity
mitsubishielectric
7.5
2022-11-30 CVE-2022-40265 Improper Input Validation vulnerability in Mitsubishielectric products
Improper Input Validation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series RJ71EN71 Firmware version "65" and prior and Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120ENCPU Network Part Firmware version "65" and prior allows a remote unauthenticated attacker to cause a Denial of Service condition by sending specially crafted packets.
network
low complexity
mitsubishielectric CWE-20
7.5
2022-11-25 CVE-2022-25164 Cleartext Storage of Sensitive Information vulnerability in Mitsubishielectric GX Works3 and MX OPC UA Module Configurator-R
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z and Mitsubishi Electric MX OPC UA Module Configurator-R versions 1.08J and prior allows a remote unauthenticated attacker to disclose sensitive information.
network
low complexity
mitsubishielectric CWE-312
7.5