Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to read or write the device values of the product and stop the operation of the programs, since MODBUS/TCP in the products does not have authentication features.
Metrics
Affected Vendors & Products
References
History
Tue, 02 Sep 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Sep 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mitsubishi Electric
Mitsubishi Electric melsec Iq-f Series |
|
| Vendors & Products |
Mitsubishi Electric
Mitsubishi Electric melsec Iq-f Series |
Mon, 01 Sep 2025 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to read or write the device values of the product and stop the operation of the programs, since MODBUS/TCP in the products does not have authentication features. | |
| Title | Information Disclosure, Information Tampering, and Denial of Service (DoS) Vulnerability in MELSEC iQ-F Series CPU module | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mitsubishi
Published: 2025-09-01T03:54:47.567Z
Updated: 2025-09-02T19:27:49.951Z
Reserved: 2025-07-10T05:59:41.803Z
Link: CVE-2025-7405
Updated: 2025-09-02T19:27:46.231Z
Status : Awaiting Analysis
Published: 2025-09-01T04:15:45.110
Modified: 2025-09-02T15:55:25.420
Link: CVE-2025-7405
No data.