CVE-2023-4625 - CVE House
Back to Database
Status published Medium CVE-2023-4625

Denial-of-Service(DoS) Vulnerability in Web server function on MELSEC Series CPU module

Vulnerability Description

Improper Restriction of Excessive Authentication Attempts vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F/iQ-R Series CPU modules Web server function allows a remote unauthenticated attacker to prevent legitimate users from logging into the Web server function for a certain period after the attacker has attempted to log in illegally by continuously attempting unauthorized login to the Web server function. The impact of this vulnerability will persist while the attacker continues to attempt unauthorized login.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-4625

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Mitsubishi Electric Corporation

View all reports →

Affected Software

MELSEC iQ-F Series FX5U-32MT/ES, MELSEC iQ-F Series FX5U-64MT/ES, MELSEC iQ-F Series FX5U-80MT/ES, MELSEC iQ-F Series FX5U-32MR/ES, MELSEC iQ-F Series FX5U-64MR/ES, MELSEC iQ-F Series FX5U-80MR/ES, MELSEC iQ-F Series FX5U-32MT/DS, MELSEC iQ-F Series FX5U-64MT/DS, MELSEC iQ-F Series FX5U-80MT/DS, MELSEC iQ-F Series FX5U-32MR/DS, MELSEC iQ-F Series FX5U-64MR/DS, MELSEC iQ-F Series FX5U-80MR/DS, MELSEC iQ-F Series FX5U-32MT/ESS, MELSEC iQ-F Series FX5U-64MT/ESS, MELSEC iQ-F Series FX5U-80MT/ESS, MELSEC iQ-F Series FX5U-32MT/DSS, MELSEC iQ-F Series FX5U-64MT/DSS, MELSEC iQ-F Series FX5U-80MT/DSS, MELSEC iQ-F Series FX5UC-32MT/D, MELSEC iQ-F Series FX5UC-64MT/D, MELSEC iQ-F Series FX5UC-96MT/D, MELSEC iQ-F Series FX5UC-32MT/DSS, MELSEC iQ-F Series FX5UC-64MT/DSS, MELSEC iQ-F Series FX5UC-96MT/DSS, MELSEC iQ-F Series FX5UC-32MT/DS-TS, MELSEC iQ-F Series FX5UC-32MT/DSS-TS, MELSEC iQ-F Series FX5UC-32MR/DS-TS, MELSEC iQ-F Series FX5UJ-24MT/ES, MELSEC iQ-F Series FX5UJ-40MT/ES, MELSEC iQ-F Series FX5UJ-60MT/ES, MELSEC iQ-F Series FX5UJ-24MR/ES, MELSEC iQ-F Series FX5UJ-40MR/ES, MELSEC iQ-F Series FX5UJ-60MR/ES, MELSEC iQ-F Series FX5UJ-24MT/ESS, MELSEC iQ-F Series FX5UJ-40MT/ESS, MELSEC iQ-F Series FX5UJ-60MT/ESS, MELSEC iQ-F Series FX5UJ-24MT/DS, MELSEC iQ-F Series FX5UJ-40MT/DS, MELSEC iQ-F Series FX5UJ-60MT/DS, MELSEC iQ-F Series FX5UJ-24MR/DS, MELSEC iQ-F Series FX5UJ-40MR/DS, MELSEC iQ-F Series FX5UJ-60MR/DS, MELSEC iQ-F Series FX5UJ-24MT/DSS, MELSEC iQ-F Series FX5UJ-40MT/DSS, MELSEC iQ-F Series FX5UJ-60MT/DSS, MELSEC iQ-F Series FX5UJ-24MT/ES-A, MELSEC iQ-F Series FX5UJ-40MT/ES-A, MELSEC iQ-F Series FX5UJ-60MT/ES-A, MELSEC iQ-F Series FX5UJ-24MR/ES-A, MELSEC iQ-F Series FX5UJ-40MR/ES-A, MELSEC iQ-F Series FX5UJ-60MR/ES-A, MELSEC iQ-F Series FX5S-30MT/ES, MELSEC iQ-F Series FX5S-40MT/ES, MELSEC iQ-F Series FX5S-60MT/ES, MELSEC iQ-F Series FX5S-80MT/ES, MELSEC iQ-F Series FX5S-30MR/ES, MELSEC iQ-F Series FX5S-40MR/ES, MELSEC iQ-F Series FX5S-60MR/ES, MELSEC iQ-F Series FX5S-80MR/ES, MELSEC iQ-F Series FX5S-30MT/ESS, MELSEC iQ-F Series FX5S-40MT/ESS, MELSEC iQ-F Series FX5S-60MT/ESS, MELSEC iQ-F Series FX5S-80MT/ESS, MELSEC iQ-R Series R00CPU, MELSEC iQ-R Series R01CPU, MELSEC iQ-R Series R02CPU, MELSEC iQ-R Series R04CPU, MELSEC iQ-R Series R08CPU, MELSEC iQ-R Series R16CPU, MELSEC iQ-R Series R32CPU, MELSEC iQ-R Series R120CPU, MELSEC iQ-R Series R04ENCPU, MELSEC iQ-R Series R08ENCPU, MELSEC iQ-R Series R16ENCPU, MELSEC iQ-R Series R32ENCPU, MELSEC iQ-R Series R120ENCPU, MELSEC iQ-R Series R08PCPU, MELSEC iQ-R Series R16PCPU, MELSEC iQ-R Series R32PCPU, MELSEC iQ-R Series R120PCPU
Vulnerable Versions:
all versions (for serial number 17X**** and later), 1.060 or later (for serial number 179**** and prior), all versions, versions 05 or later, versions 35 or later, versions 37 or later

Timeline

Official Publish: November 6th, 2023
Last Modified: February 27th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Weaknesses (CWE)