CVE-2023-1424: Denial-of-Service and Remote Code Execution Vulnerability in MELSEC Series CPU module
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on a target product by sending specially crafted packets. A system reset of the product is required for recovery from a denial of service (DoS) condition and malicious code execution.
Other sources
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules and MELSEC iQ-R Series CPU modules allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on a target product by sending specially crafted packets. A system reset of the product is required for recovery from a denial of service (DoS) condition and malicious code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1424?
CVE-2023-1424 is classified as a high severity vulnerability due to its potential to cause denial of service and execute malicious code.
How do I fix CVE-2023-1424?
To mitigate CVE-2023-1424, it is recommended to update to the latest firmware provided by Mitsubishi Electric for the affected products.
Which devices are affected by CVE-2023-1424?
The CVE-2023-1424 vulnerability affects various Mitsubishi Electric MELSEC iQ-F Series CPU modules, including specific models of the FX5U and FX5UC series.
Can CVE-2023-1424 be exploited remotely?
Yes, CVE-2023-1424 can be exploited by a remote unauthenticated attacker, allowing them to leverage the vulnerability from outside the network.
What types of attacks can CVE-2023-1424 facilitate?
CVE-2023-1424 can facilitate denial of service (DoS) attacks or enable the execution of arbitrary code on vulnerable devices.