CVE-2025-5241
BaseFortify
Publication date: 2025-07-11
Last updated on: 2025-07-15
Assigner: Mitsubishi Electric Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mitsubishi | electric_melsec_iq-f_series | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-645 | The product contains an account lockout protection mechanism, but the mechanism is too restrictive and can be triggered too easily, which allows attackers to deny service to legitimate users by causing their accounts to be locked out. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Overly Restrictive Account Lockout Mechanism in Mitsubishi Electric Corporation MELSEC iQ-F Series. It allows a remote unauthenticated attacker to repeatedly attempt to login with incorrect passwords, causing legitimate users to be locked out for a certain period or until the product is reset.
How can this vulnerability impact me? :
The vulnerability can impact you by preventing legitimate users from logging into the system for a certain period or until the product is reset, potentially causing denial of service or disruption of normal operations.