CVE-2023-4699

CRITICAL

Mitsubishielectric Fx3u-32mt/es Firmware - Missing Authentication

Title source: rule

Description

Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC-F Series CPU modules, MELSEC iQ-F Series, MELSEC iQ-R series CPU modules, MELSEC iQ-R series, MELSEC iQ-L series, MELSEC Q series, MELSEC-L series, Mitsubishi Electric CNC M800V/M80V series, Mitsubishi Electric CNC M800/M80/E80 series and Mitsubishi Electric CNC M700V/M70V/E70 series allows a remote unauthenticated attacker to execute arbitrary commands by sending specific packets to the affected products. This could lead to disclose or tamper with information by reading or writing control programs, or cause a denial-of-service (DoS) condition on the products by resetting the memory contents of the products to factory settings or resetting the products remotely.

Exploits (1)

nomisec STUB 1 stars
by Scottzxor · poc
https://github.com/Scottzxor/Citrix-Bleed-Buffer-Overread-Demo

Scores

CVSS v3 10.0
EPSS 0.0091
EPSS Percentile 75.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-345 CWE-306
Status published
Products (50)
mitsubishielectric/fx3g-14mr\/ds_firmware
mitsubishielectric/fx3g-14mr\/es-a_firmware
mitsubishielectric/fx3g-14mr\/es_firmware
mitsubishielectric/fx3g-14mt\/ds_firmware
mitsubishielectric/fx3g-14mt\/dss_firmware
mitsubishielectric/fx3g-14mt\/es-a_firmware
mitsubishielectric/fx3g-14mt\/es_firmware
mitsubishielectric/fx3g-14mt\/ess_firmware
mitsubishielectric/fx3g-24mr\/ds_firmware
mitsubishielectric/fx3g-24mr\/es-a_firmware
... and 40 more
Published Nov 06, 2023
Tracked Since Feb 18, 2026