CVE-2023-6815
—CVSS 3.1
6.5 medium
EPSS
<1%p51
Published
()
Modified
Description
Incorrect Privilege Assignment vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series Safety CPU R08/16/32/120SFCPU all versions and MELSEC iQ-R Series SIL2 Process CPU R08/16/32/120PSFCPU all versions allows a remote authenticated attacker who has logged into the product as a non-administrator user to disclose the credentials (user ID and password) of a user with a lower access level than the attacker by sending a specially crafted packet.
- Vendors
- mitsubishielectric
- Products
- r08sfcpu firmware, r16sfcpu firmware, r32sfcpu firmware, r120sfcpu firmware, r08psfcpu firmware, r16psfcpu firmware, r32psfcpu firmware, r120psfcpu firmware
- Weakness
- CWE-266
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.