CVE-2023-2061
02.06.2023, 05:15
Use of Hard-coded Password vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to obtain a hard-coded password and access to the module via FTP.Enginsight
Vendor | Product | Version |
---|---|---|
mitsubishielectric | fx5-enet\/ip_firmware | - |
mitsubishielectric | sw1dnn-eipct-bd_firmware | - |
mitsubishielectric | rj71eip91_firmware | - |
mitsubishielectric | sw1dnn-eipctfx5-bd_firmware | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-259 - Use of Hard-coded PasswordThe software contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.
- CWE-798 - Use of Hard-coded CredentialsThe software contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.