#VU77046 Weak password requirements in Mitsubishi Electric products - CVE-2023-2060 

 

#VU77046 Weak password requirements in Mitsubishi Electric products - CVE-2023-2060

Published: June 7, 2023


Vulnerability identifier: #VU77046
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-2060
CWE-ID: CWE-521
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
RJ71EIP91
SW1DNN-EIPCT-BD
FX5-ENET/IP
SW1DNN-EIPCTFX5-BD
Software vendor:
Mitsubishi Electric

Description

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to weak password requirements in FTP function on EtherNet/IP module. A remote attacker can access to the module via FTP by dictionary attack or password sniffing.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links