First published: Tue Feb 27 2024(Updated: )
Insufficient Resource Pool vulnerability in Ethernet function of Mitsubishi Electric Corporation MELSEC iQ-R series CPU module, MELSEC iQ-L series CPU module, MELSEC iQ-R Ethernet Interface Module, MELSEC iQ-R CC-Link IE TSN Master/Local Module, CC-Link IE TSN Remote I/O Module, CC-Link IE TSN Analog-Digital Converter Module, CC-Link IE TSN Digital-Analog Converter Module, CC-Link IE TSN - CC-Link IE Field Network Bridge Module, CC-Link IE TSN - AnyWireASLINK Bridge Module, CC-Link IE TSN FPGA Module, CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY, MELSEC iQ-R Motion Module, MELSEC iQ-L Motion Module, MELSEC iQ-F FX5 Motion Module, MELSEC iQ-F Series CPU module, MELSEC iQ-F Series Ethernet module, MELSEC iQ-F Series Ethernet/IP module, MELSEC iQ-F Series OPC UA Module, MELSEC iQ-F Series CC-Link IE TSN master/local module, GOT2000 Series CC-Link IE TSN Communication Unit, FR-A800-E series inverters, FR-F800-E series inverters, FR-E800-E series inverters, INVERTER CC-Link IE TSN Plug-in option, INVERTER CC-Link IE TSN Safety Plug-in option, INVERTER CC-Link IE TSN communication function built-in type, MR-J5 series AC Servos MELSERVO, MR-JET series AC Servos MELSERVO, MR-MD333G series AC Servos MELSERVO, MR-JE series AC Servos MELSERVO, MELSERVO-J4 AC Servos MELSERVO and Embedded Type Servo System Controller allow a remote attacker to cause a temporary Denial of Service condition for a certain period of time in Ethernet communication of the products by performing TCP SYN Flood attack.
Credit: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishi Electric MELSEC iQ-R series CPU module | ||
Mitsubishi Electric MELSEC iQ-L series CPU module | ||
Mitsubishi Electric MELSEC iQ-R Ethernet Interface Module | ||
Mitsubishi Electric MELSEC iQ-R CC-Link IE TSN Master/Local Module | ||
Mitsubishi Electric CC-Link IE TSN Remote I/O Module | ||
Mitsubishi Electric CC-Link IE TSN Analog-Digital Converter Module | ||
Mitsubishi Electric CC-Link IE TSN Digital-Analog Converter Module | ||
Mitsubishi Electric CC-Link IE TSN - CC-Link IE Field Network Bridge Module | ||
Mitsubishi Electric CC-Link IE TSN - AnyWireASLINK Bridge Module | ||
Mitsubishi Electric CC-Link IE TSN FPGA Module | ||
Mitsubishi Electric CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY | ||
Mitsubishi Electric MELSEC iQ-R Motion Module | ||
Mitsubishi Electric MELSEC iQ-L Motion Module | ||
Mitsubishi Electric MELSEC iQ-F FX5 Motion Module | ||
Mitsubishi Electric MELSEC iQ-F Series CPU module | ||
Mitsubishi Electric MELSEC iQ-F Series Ethernet module | ||
Mitsubishi Electric MELSEC iQ-F Series Ethernet/IP module | ||
Mitsubishi Electric MELSEC iQ-F Series OPC UA Module | ||
Mitsubishi Electric MELSEC iQ-F Series CC-Link IE TSN master/local module | ||
Mitsubishi Electric GOT2000 Series CC-Link IE TSN Communication Unit | ||
Mitsubishi Electric FR-A800-E series inverters | ||
Mitsubishi Electric FR-F800-E series inverters | ||
Mitsubishi Electric FR-E800-EPA Series | ||
Mitsubishi Electric INVERTER CC-Link IE TSN Plug-in option | ||
Mitsubishi Electric INVERTER CC-Link IE TSN Safety Plug-in option | ||
Mitsubishi Electric INVERTER CC-Link IE TSN communication function built-in type | ||
Mitsubishi Electric MR-J5 series AC Servos MELSERVO | ||
Mitsubishi Electric MR-JET series AC Servos MELSERVO | ||
Mitsubishi Electric MR-MD333G series AC Servos MELSERVO | ||
Mitsubishi Electric MR-JE series AC Servos MELSERVO | ||
Mitsubishi Electric MELSERVO-J4 AC Servos MELSERVO | ||
Mitsubishi Electric Embedded Type Servo System Controller |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-7033 is classified as critical due to insufficient resource management that may lead to denial of service.
To fix CVE-2023-7033, users should apply the latest firmware update provided by Mitsubishi Electric for affected devices.
CVE-2023-7033 affects various Mitsubishi Electric products including MELSEC iQ-R and iQ-L series CPU modules and various CC-Link IE TSN modules.
Exploitation of CVE-2023-7033 can result in denial of service, impacting the functionality of the affected Ethernet devices.
As of now, there are no reported incidents of active exploitation of CVE-2023-7033.