CVE-2022-25163: Input Validation
Improper Input Validation vulnerability in Mitsubishi Electric MELSEC-Q Series QJ71E71-100 first 5 digits of serial number "24061" or prior, Mitsubishi Electric MELSEC-L series LJ71E71-100 first 5 digits of serial number "24061" or prior and Mitsubishi Electric MELSEC iQ-R Series RD81MES96N firmware version "08" or prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on the target products by sending specially crafted packets.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-25163.
What software is affected by this vulnerability?
The Mitsubishi Electric MELSEC-Q Series QJ71E71-100 firmware with a version up to exclusive 24062 and Mitsubishi Electric MELSEC L Series LJ71E71-100 firmware with a version up to exclusive 24062 are affected by this vulnerability.
What is the severity of CVE-2022-25163?
The severity of CVE-2022-25163 is critical with a CVSS score of 9.8.
How does this vulnerability manifest?
This vulnerability is a result of improper input validation in the first 5 digits of the serial number.
Where can I find more information about this vulnerability?
More information about this vulnerability can be found at the following references: [Reference 1](https://jvn.jp/vu/JVNVU92561747/index.html) and [Reference 2](https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-006_en.pdf).