Vulnerabilities > Mitsubishielectric > Low

DATE CVE VULNERABILITY TITLE RISK
2022-01-21 CVE-2022-23129 Cleartext Storage of Sensitive Information vulnerability in multiple products
Plaintext Storage of a Password vulnerability in Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior and ICONICS GENESIS64 versions 10.90 to 10.97 allows a local authenticated attacker to gain authentication information and to access the database illegally.
local
low complexity
iconics mitsubishielectric CWE-312
2.1
2020-12-14 CVE-2020-5665 Improper Handling of Exceptional Conditions vulnerability in Mitsubishielectric Melsec Iq-F Fx5U CPU Firmware 1.060
Improper check or handling of exceptional conditions in MELSEC iQ-F series FX5U(C) CPU unit firmware version 1.060 and earlier allows an attacker to cause a denial-of-service (DoS) condition on program execution and communication by sending a specially crafted ARP packet.
low complexity
mitsubishielectric CWE-755
3.3
2020-11-02 CVE-2020-5657 Argument Injection or Modification vulnerability in Mitsubishielectric products
Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network Interface Module First 2 digits of serial number are '02' or before, RJ71PN92 PROFINET IO Controller Module First 2 digits of serial number are '01' or before, RD81DL96 High Speed Data Logger Module First 2 digits of serial number are '08' or before, RD81MES96N MES Interface Module First 2 digits of serial number are '04' or before, and RD81OPC96 OPC UA Server Module First 2 digits of serial number are '04' or before) allows unauthenticated attackers on adjacent network to stop the network functions of the products via a specially crafted packet.
low complexity
mitsubishielectric CWE-88
3.3