CVE-2025-5241CWE-645

Denial-of-Service Vulnerability in MELSEC iQ-F Series

Medium · published July 11, 2025

CVSS v3.1
5.3
EPSS
0%
Percentile
32.4
In the wild
Unconfirmed
What it is

Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series allows a remote unauthenticated attacker to lockout legitimate users for a certain period by repeatedly attempting to login with incorrect passwords. The legitimate users will be unable to login until a certain period has passed after the lockout or until the product is reset.

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS v4.0
Not supplied
EPSS
0.00392 · 32.4th percentile
Weakness
CWE-645 · Overly Restrictive Account Lockout Mechanism
Published
2025-07-11T00:16Z
EPSS history
Timeline
  • 11 JUL 00:16Z
    Denial-of-Service Vulnerability in MELSEC iQ-F Series
    cvelistv5