First published: Mon Feb 13 2017(Updated: )
An issue was discovered in Mitsubishi Electric Automation MELSEC-Q series Ethernet interface modules QJ71E71-100, all versions, QJ71E71-B5, all versions, and QJ71E71-B2, all versions. The affected Ethernet interface module is connected to a MELSEC-Q PLC, which may allow a remote attacker to connect to the PLC via Port 5002/TCP and cause a denial of service, requiring the PLC to be reset to resume operation. This is caused by an Unrestricted Externally Accessible Lock.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishi Electric QJ71E71-100 Firmware | ||
Mitsubishi Electric QJ71E71-100 Firmware | ||
Mitsubishi Electric QJ71E71-B5 | ||
Mitsubishi Electric QJ71E71-B5 | ||
Mitsubishi Electric QJ71E71-B2 Firmware | ||
Mitsubishi Electric QJ71E71-B2 Firmware | ||
All of | ||
Mitsubishi Electric QJ71E71-100 Firmware | ||
Mitsubishi Electric QJ71E71-100 Firmware | ||
All of | ||
Mitsubishi Electric QJ71E71-B5 | ||
Mitsubishi Electric QJ71E71-B5 | ||
All of | ||
Mitsubishi Electric QJ71E71-B2 Firmware | ||
Mitsubishi Electric QJ71E71-B2 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8368 has been rated as a medium severity vulnerability.
To fix CVE-2016-8368, you should update the firmware on affected Mitsubishi Electric Automation MELSEC-Q Ethernet interface modules.
CVE-2016-8368 affects the Mitsubishi Electric Automation MELSEC-Q series Ethernet interface modules QJ71E71-100, QJ71E71-B5, and QJ71E71-B2.
Yes, CVE-2016-8368 allows a remote attacker to connect and potentially exploit the affected Ethernet interface modules.
Exploiting CVE-2016-8368 could lead to unauthorized access to the MELSEC-Q PLC, jeopardizing the security and operation of the automation system.