First published: Sat Oct 03 2015(Updated: )
The HTTP application on Mitsubishi Electric MELSEC FX3G PLC devices before April 2015 allows remote attackers to cause a denial of service (device outage) via a long parameter.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishi Electric MELSEC-F FX3G-xMy/ES-A |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3938 has been classified as a high severity vulnerability, as it can lead to a denial of service on affected devices.
To fix CVE-2015-3938, update the firmware of Mitsubishi Electric MELSEC FX3G PLC devices to a version released after April 2015.
CVE-2015-3938 allows remote attackers to execute a denial of service attack by sending a long parameter to the HTTP application.
CVE-2015-3938 affects Mitsubishi Electric MELSEC FX3G PLC devices prior to April 2015.
Yes, CVE-2015-3938 is exploitable by remote attackers, leading to device outages.