CISA issued an updated industrial control systems advisory for Mitsubishi Electric MELSEC iQ-F, iQ-R, Q, and L series products affected by a plaintext password storage flaw tracked as CVE-2023-0457 and classified as CWE-256. The vulnerability allows an unauthenticated remote attacker to recover plaintext credentials from project files and potentially use them to authenticate to associated FTP or web servers. CISA assigned the issue a CVSS v3 score of 7.5 and said the weakness affects multiple CPU and Ethernet modules across the listed MELSEC product families.
Mitsubishi Electric and CISA advised operators to reduce exposure by encrypting project files and communications, restricting network access with firewalls or VPNs, preferring LAN-only deployments where feasible, limiting physical access, and enabling IP filtering on supported iQ-F and iQ-R devices. The updated notice builds on an earlier CISA advisory covering the MELSEC iQ-F series, while CISA said it is not aware of public exploits specifically targeting this vulnerability.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CISA published Update A for the Mitsubishi Electric advisory, stating that MELSEC iQ-F, iQ-R, Q, and L series products were affected by CVE-2023-0457. The update described the risk of unauthenticated attackers obtaining plaintext credentials from project files and included mitigation guidance; CISA said it was unaware of public exploitation targeting the flaw.
CISA published ICS advisory ICSA-20-345-01 covering a plaintext password storage flaw affecting Mitsubishi Electric MELSEC iQ-F Series products. The issue, later tracked as CVE-2023-0457, could expose credentials stored in project files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.