First published: Thu Jun 02 2022(Updated: )
Improper Input Validation vulnerability in Mitsubishi Electric MELSEC-Q Series QJ71E71-100 first 5 digits of serial number "24061" or prior, Mitsubishi Electric MELSEC-L series LJ71E71-100 first 5 digits of serial number "24061" or prior and Mitsubishi Electric MELSEC iQ-R Series RD81MES96N firmware version "08" or prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on the target products by sending specially crafted packets.
Credit: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishielectric Melsec Iq-rd81mes96n Firmware | <09 | |
Mitsubishi Electric Melsec Iq-rd81mes96n | ||
Mitsubishi Melsec QJ71E71-100 | <24062 | |
Mitsubishi Melsec QJ71E71-100 Firmware | ||
Mitsubishi Electric Lj71e71-100 Firmware | <24062 | |
Mitsubishi Electric LJ71E71-100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-25163.
The Mitsubishi Electric MELSEC-Q Series QJ71E71-100 firmware with a version up to exclusive 24062 and Mitsubishi Electric MELSEC L Series LJ71E71-100 firmware with a version up to exclusive 24062 are affected by this vulnerability.
The severity of CVE-2022-25163 is critical with a CVSS score of 9.8.
This vulnerability is a result of improper input validation in the first 5 digits of the serial number.
More information about this vulnerability can be found at the following references: [Reference 1](https://jvn.jp/vu/JVNVU92561747/index.html) and [Reference 2](https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-006_en.pdf).