CVE-2023-4699
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC-F Series CPU modules, MELSEC iQ-F Series, MELSEC iQ-R series CPU modules, MELSEC iQ-R series, MELSEC iQ-L series, MELSEC Q series, MELSEC-L series,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.75%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC-F Series CPU modules, MELSEC iQ-F Series, MELSEC iQ-R series CPU modules, MELSEC iQ-R series, MELSEC iQ-L series, MELSEC Q series, MELSEC-L series, Mitsubishi Electric CNC M800V/M80V series, Mitsubishi Electric CNC M800/M80/E80 series and Mitsubishi Electric CNC M700V/M70V/E70 series allows a remote unauthenticated attacker to execute arbitrary commands by sending specific packets to the affected products. This could lead to disclose or tamper with information by reading or writing control programs, or cause a denial-of-service (DoS) condition on the products by resetting the memory contents of the products to factory settings or resetting the products remotely.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- EPSS
- 0.75% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306, CWE-345
- Affected
- mitsubishielectric/fx3u-32mt\/es firmware · mitsubishielectric/fx3u-48mt\/es firmware · mitsubishielectric/fx3u-64mt\/es firmware · mitsubishielectric/fx3u-80mt\/es firmware · mitsubishielectric/fx3u-128mt\/e firmware · mitsubishielectric/fx3u-16mt\/es firmware · mitsubishielectric/fx3u-16mr\/es firmware · mitsubishielectric/fx3u-32mr\/es firmware · mitsubishielectric/fx3u-48mr\/es firmware · mitsubishielectric/fx3u-64mr\/es firmware · mitsubishielectric/fx3u-80mr\/es firmware · mitsubishielectric/fx3u-128mr\/es firmware · mitsubishielectric/fx3u-16mt\/ess firmware · mitsubishielectric/fx3u-32mt\/ess firmware · mitsubishielectric/fx3u-48mt\/ess firmware · mitsubishielectric/fx3u-64mt\/ess firmware · mitsubishielectric/fx3u-80mt\/ess firmware · mitsubishielectric/fx3u-128mt\/ess firmware · mitsubishielectric/fx3u-16mt\/ds firmware · mitsubishielectric/fx3u-32mt\/ds firmware · +40 more
- Source
- Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
References
- https://jvn.jp/vu/JVNVU94620134/Third Party Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-306-03Third Party Advisory, US Government Resource
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-013_en.pdfVendor Advisory
- https://jvn.jp/vu/JVNVU94620134/Third Party Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-306-03Third Party Advisory, US Government Resource
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-013_en.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.