#VU61827 Cleartext storage of sensitive information in MELSEC iQ-F series FX5U(C) CPU module and MELSEC iQ-F Series FX5UJ CPU module - CVE-2022-25160
Published: April 4, 2022 / Updated: June 2, 2022
MELSEC iQ-F series FX5U(C) CPU module
MELSEC iQ-F Series FX5UJ CPU module
Mitsubishi Electric
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the password hash is saved in cleartext. A remote attacker can disclose a file in a legitimate user's product by using previously eavesdropped cleartext information and counterfeit a legitimate user’s system.