CVE-2023-4562
Improper Authentication vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules allows a remote unauthenticated attacker to obtain sequence programs from the product or write malicious sequence programs or improper data in the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.85%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Improper Authentication vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules allows a remote unauthenticated attacker to obtain sequence programs from the product or write malicious sequence programs or improper data in the product without authentication by sending illegitimate messages.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 0.85% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- mitsubishielectric/fx3g-14 mr\/ds firmware · mitsubishielectric/fx3g-14 mr\/es firmware · mitsubishielectric/fx3g-14 mt\/ds firmware · mitsubishielectric/fx3g-14 mt\/dss firmware · mitsubishielectric/fx3g-14 mt\/es firmware · mitsubishielectric/fx3g-14 mt\/ess firmware · mitsubishielectric/fx3g-14mr\/ds firmware · mitsubishielectric/fx3g-14mr\/es firmware · mitsubishielectric/fx3g-14mr\/es-a firmware · mitsubishielectric/fx3g-14mt\/ds firmware · mitsubishielectric/fx3g-14mt\/dss firmware · mitsubishielectric/fx3g-14mt\/es firmware · mitsubishielectric/fx3g-14mt\/es-a firmware · mitsubishielectric/fx3g-14mt\/ess firmware · mitsubishielectric/fx3g-232adp\(-mb\) firmware · mitsubishielectric/fx3g-24 mr\/ds firmware · mitsubishielectric/fx3g-24 mr\/es firmware · mitsubishielectric/fx3g-24 mt\/ds firmware · mitsubishielectric/fx3g-24 mt\/dss firmware · mitsubishielectric/fx3g-24 mt\/es firmware · +40 more
- Source
- Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
References
- https://jvn.jp/vu/JVNVU90509290/Third Party Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-285-13Third Party Advisory, US Government Resource
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-012_en.pdfVendor Advisory
- https://jvn.jp/vu/JVNVU90509290/Third Party Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-285-13Third Party Advisory, US Government Resource
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-012_en.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.