CVE-2023-3346: Denial of Service (DoS) and Remote Code Execution Vulnerability in MITSUBISHI CNC Series
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition and execute arbitrary code on the product by sending specially crafted packets. In addition, system reset is required for recovery.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2023-3346.
What is the severity of CVE-2023-3346?
The severity of CVE-2023-3346 is critical with a CVSS score of 9.8.
What is the affected software for CVE-2023-3346?
The affected software for CVE-2023-3346 is Mitsubishielectric C80 Firmware, Mitsubishielectric E70 Firmware, Mitsubishielectric E80 Firmware, Mitsubishielectric M70v Firmware, Mitsubishielectric M720vs Firmware, Mitsubishielectric M720vs 15-type Firmware, Mitsubishielectric M720vw Firmware, Mitsubishielectric M730vs Firmware, Mitsubishielectric M730vs 15-type Firmware, Mitsubishielectric M730vw Firmware, Mitsubishielectric M750vs Firmware, Mitsubishielectric M750vs 15-type Firmware, Mitsubishielectric M750vw Firmware, Mitsubishielectric M80 Firmware, Mitsubishielectric M800s Firmware, Mitsubishielectric M800vs Firmware, Mitsubishielectric M800vw Firmware, Mitsubishielectric M800w Firmware, Mitsubishielectric M80v Firmware, Mitsubishielectric M80vw Firmware, and Mitsubishielectric M80w Firmware.
How does CVE-2023-3346 impact the affected software?
CVE-2023-3346 allows a remote unauthenticated attacker to cause a Denial of Service (DoS) condition and execute arbitrary code on the affected software.
Are there any official references for CVE-2023-3346?
Yes, you can find official references for CVE-2023-3346 at the following links: [Mitsubishielectric PSIRT PDF](https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-007_en.pdf), [CISA Advisory](https://www.cisa.gov/news-events/ics-advisories/icsa-23-208-03), [JVN](https://jvn.jp/vu/JVNVU90352157/index.html).