ICSA-24-030-03
·
Published 2024-01-30
·
View on CISA ICS-CERT ↗
Mitsubishi Electric MELSEC WS Series Ethernet Interface Module
CVSS 5.9
MEDIUM
Risk Summary
Successful exploitation of this vulnerability could allow an unauthorized attacker to login to the modules and disclose or tamper with the programs and parameters in the modules.
CVEs (1)
Remediations
- Mitsubishi Electric recommends that users take the following mitigation measures to minimize the risk of exploiting this vulnerability:
- Use a virtual private network (VPN), etc. to encrypt the communication between affected products and the peer.
- Use a firewall or virtual private network (VPN), etc. to prevent unauthorized access when Internet access is required.
- Use within a LAN and block access from untrusted networks and hosts through firewalls.
- Restrict physical access to affected products and to personal computers and network devices located in the LAN to which the affected products are connected.
- For more information, see Mitsubishi Electric's security advisory.
Affected Vendors
Mitsubishi Electric
Affected Products (1)
Mitsubishi Electric
·
WS0-GETH00200
vers:all/*
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more