CVE-2023-4562

CRITICAL

Mitsubishi Electric Corporation MELSEC-F Series - Auth Bypass

Title source: llm

Description

Improper Authentication vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules allows a remote unauthenticated attacker to obtain sequence programs from the product or write malicious sequence programs or improper data in the product without authentication by sending illegitimate messages.

Scores

CVSS v3 9.1
EPSS 0.0023
EPSS Percentile 45.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Classification

CWE
CWE-287
Status published

Affected Products (50)

mitsubishielectric/fx3g-14_mr\/ds_firmware
mitsubishielectric/fx3g-14_mr\/es_firmware
mitsubishielectric/fx3g-14_mt\/ds_firmware
mitsubishielectric/fx3g-14_mt\/dss_firmware
mitsubishielectric/fx3g-14_mt\/es_firmware
mitsubishielectric/fx3g-14_mt\/ess_firmware
mitsubishielectric/fx3g-14mr\/ds_firmware
mitsubishielectric/fx3g-14mr\/es_firmware
mitsubishielectric/fx3g-14mr\/es-a_firmware
mitsubishielectric/fx3g-14mt\/ds_firmware
mitsubishielectric/fx3g-14mt\/dss_firmware
mitsubishielectric/fx3g-14mt\/es_firmware
mitsubishielectric/fx3g-14mt\/es-a_firmware
mitsubishielectric/fx3g-14mt\/ess_firmware
mitsubishielectric/fx3g-232adp\(-mb\)_firmware
... and 35 more

Timeline

Published Oct 13, 2023
Tracked Since Feb 18, 2026