Weak Encoding for Password in Mitsubishi Electric products - CVE-2023-0525

 

Weak Encoding for Password in Mitsubishi Electric products - CVE-2023-0525

Published: August 4, 2023


Vulnerability identifier: #VU78942
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-0525
CWE-ID: CWE-261
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to weak encoding for password in the Data Transfer Security function. A remote attacker can sniff packets containing encrypted passwords and obtain plaintext passwords.


Affected software

GT Designer3
GOT2000 GT21 model
GT SoftGOT2000
GOT2000 GT23 model
GOT2000 GT25 model
GOT2000 GT27 model
GOT SIMPLE GS21 model
GOT SIMPLE GS25 model

How to mitigate CVE-2023-0525

Install updates from vendor's website.

GT Designer3 - update to 1.300N
GOT2000 GT21 model - update to 01.50.000
GT SoftGOT2000 - update to 1.300N
GOT2000 GT23 model - update to 01.50.000
GOT2000 GT25 model - update to 01.50.000
GOT2000 GT27 model - update to 01.50.000
GOT SIMPLE GS21 model - update to 01.50.000
GOT SIMPLE GS25 model - update to 01.50.000

External References

Related Security Bulletins