#VU78942 Weak Encoding for Password in Mitsubishi Electric products - CVE-2023-0525
Published: August 4, 2023
Vulnerability identifier: #VU78942
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-0525
CWE-ID: CWE-261
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
GT Designer3
GOT2000 GT21 model
GT SoftGOT2000
GOT2000 GT23 model
GOT2000 GT25 model
GOT2000 GT27 model
GOT SIMPLE GS21 model
GOT SIMPLE GS25 model
GT Designer3
GOT2000 GT21 model
GT SoftGOT2000
GOT2000 GT23 model
GOT2000 GT25 model
GOT2000 GT27 model
GOT SIMPLE GS21 model
GOT SIMPLE GS25 model
Software vendor:
Mitsubishi Electric
Mitsubishi Electric
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to weak encoding for password in the Data Transfer Security function. A remote attacker can sniff packets containing encrypted passwords and obtain plaintext passwords.
Remediation
Install updates from vendor's website.