Mitsubishi Electric MELSEC iQ-R Series/iQ-F Series Weak Password Requirements (CVE-2023-2060)

high Tenable OT Security Plugin ID 501224

Synopsis

The remote OT asset is affected by a vulnerability.

Description

Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to access to the module via FTP by dictionary attack or password sniffing.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

The following text was originally created by the Cybersecurity and Infrastructure Security Agency (CISA). The original can be found at CISA.gov.

Mitsubishi Electric recommends that users of the affected products take the following actions:

- RJ71EIP91: Consider replacing with the next generation model, CC-Link IE TSN Plus Master/Local Module RJ71GN11-EIP.
- RJ71EIP91 firmware version "06" or later: The FTP function can be disabled in firmware version "06" or later. To prevent unauthorized access from outside, set the connection to 'Deny connection' in the EtherNet/IP Configuration Tool Connection Permission Change function and disable the module's FTP function, except when configuring with the EtherNet/IP Configuration Tool. However, firmware versions earlier than "06" cannot be updated to version "06" or later.
For detailed configuration instructions, refer to the following manuals: MELSEC iQ-R EtherNet/IP Module User's Manual (Application) "1.3 Ethernet/IP Configuration Tool Connectable Function".
- FX5-ENET/IP: There are no plans to release a fixed version, so take mitigations and workarounds below. In addition, consider replacing it with the next-generation model, the EtherNet/IP Module FX5-EIP.
- FX5-ENET/IP: Use IP filter function to block access from untrusted hosts. For details on the IP filter function, refer to the following manual: "12.1 IP Filter Function" in the MELSEC iQ-F FX5 User's Manual (Ethernet Communication).
- FX5-ENET/IP firmware version "1.106" or later: The FTP function can be disabled. To prevent unauthorized access from outside, set the connection to "Deny connection" in the EtherNet/IP Configuration Tool for FX5-ENET/IP Tool connection setting change function and disable the module's FTP function, except when configuring with the EtherNet/IP Configuration Tool for FX5-ENET/IP. For detailed configuration instructions, refer to the following manuals: "Tool connection setting change function" in the "Details of buffer memory addresses" in the "Appendix 4 Buffer Memory" in the "MELSEC iQ-F FX5 EtherNet/IP Module User's Manual."
- SW1DNN-EIPCT-BD: Download and update the fixed version Software version "1.02C" or later
- SW1DNN-EIPCTFX5-BD: Download and update the fixed version Software version "1.02C" or later.

Mitsubishi Electric recommends that customers take the following mitigation measures to minimize the risk of exploiting these vulnerabilities common to RJ71EIP91 and FX5-ENET/IP:

- Use a firewall, virtual private network (VPN), etc. to prevent unauthorized access when Internet access is required.
- Use within a LAN and block access from untrusted networks and hosts through firewalls.
- Restrict physical access to prevent untrusted devices from connecting to the LAN to which the affected product is connected.
- Avoid uploading/downloading files directly using FTP, and use the EtherNet/IP configuration tool. Also, do not open the downloaded file with anything other than the EtherNet/IP configuration tool.

Mitsubishi Electric recommends that customers take the following mitigation measures to minimize the risk of exploitation of these vulnerabilities common to SW1DNN-EIPCT-BD and SW1DNN-EIPCTFX5-BD:

- Allow only trusted users to log in or remotely log in.
- Ensure that no one else can view the screen of a user from behind while using the product.
- If you leave your desk while using the product, lock your PC to prevent others from using it.
- Operate the PC using the product within a LAN and block access from untrusted networks or hosts.
- Restrict physical access to the PC on which the product is installed, as well as the PCs and network devices that can communicate with the product.
- Install antivirus software on the PCs that use the product, as well as on the PCs that can communicate with the product.
- Do not open untrusted files or click on untrusted links.

For specific update instructions and additional details see the Mitsubishi Electric advisory.

See Also

http://www.nessus.org/u?6fa8885c

https://jvn.jp/vu/JVNVU92908006

https://www.cisa.gov/news-events/ics-advisories/icsa-23-157-02

Plugin Details

Severity: High

ID: 501224

File Name: tenable_ot_mitsubishi_CVE-2023-2060.nasl

Version: 1.8

Type: remote

Family: Tenable.ot

Published: 6/30/2023

Updated: 2/14/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2023-2060

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:mitsubishielectric:rj71eip91_firmware:-, cpe:/o:mitsubishielectric:fx5-enet%2fip_firmware:-

Required KB Items: Tenable.ot/Mitsubishi

Exploit Ease: No known exploits are available

Patch Publication Date: 6/2/2023

Vulnerability Publication Date: 6/2/2023

Reference Information

CVE: CVE-2023-2060

CWE: 521

ICSA: 23-157-02