# CVE-2023-2062

## Summary

- **CVE ID:** CVE-2023-2062
- **Severity:** MEDIUM
- **CVSS Score:** 6.2 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-549
- **Published:** Jun 2, 2023
- **Last Modified:** Mar 13, 2026

## Description

Missing Password Field Masking vulnerability in Mitsubishi Electric Corporation EtherNet/IP configuration tools SW1DNN-EIPCT-BD and SW1DNN-EIPCTFX5-BD allows a remote unauthenticated attacker to know the password for MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP. This vulnerability results in authentication bypass vulnerability, which allows the attacker to access MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP via FTP.

## Affected Products

- Mitsubishi Electric Corporation — EtherNet/IP Configuration tool for RJ71EIP91 SW1DNN-EIPCT-BD (Software version "1.01B" and prior)
- Mitsubishi Electric Corporation — EtherNet/IP Configuration tool for FX5-ENET/IP SW1DNN-EIPCTFX5-BD (Software version "1.01B" and prior)

## References

- [CNA](https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2023-004.pdf)
- [CNA](https://jvn.jp/vu/JVNVU92908006)
- [CNA](https://www.cisa.gov/news-events/ics-advisories/icsa-23-157-02)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.04%
- **EPSS Percentile:** 12.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._