CVE-2023-7033: Medium severity Mitsubishi Electric MELSEC iQ-R series CPU module vulnerability
Insufficient Resource Pool vulnerability in Ethernet function of Mitsubishi Electric Corporation MELSEC iQ-R series CPU module, MELSEC iQ-L series CPU module, MELSEC iQ-R Ethernet Interface Module, MELSEC iQ-R CC-Link IE TSN Master/Local Module, CC-Link IE TSN Remote I/O Module, CC-Link IE TSN Analog-Digital Converter Module, CC-Link IE TSN Digital-Analog Converter Module, CC-Link IE TSN - CC-Link IE Field Network Bridge Module, CC-Link IE TSN - AnyWireASLINK Bridge Module, CC-Link IE TSN FPGA Module, CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY, MELSEC iQ-R Motion Module, MELSEC iQ-L Motion Module, MELSEC iQ-F FX5 Motion Module, MELSEC iQ-F Series CPU module, MELSEC iQ-F Series Ethernet module, MELSEC iQ-F Series Ethernet/IP module, MELSEC iQ-F Series OPC UA Module, MELSEC iQ-F Series CC-Link IE TSN master/local module, GOT2000 Series CC-Link IE TSN Communication Unit, FR-A800-E series inverters, FR-F800-E series inverters, FR-E800-E series inverters, INVERTER CC-Link IE TSN Plug-in option, INVERTER CC-Link IE TSN Safety Plug-in option, INVERTER CC-Link IE TSN communication function built-in type, MR-J5 series AC Servos MELSERVO, MR-JET series AC Servos MELSERVO, MR-MD333G series AC Servos MELSERVO, MR-JE series AC Servos MELSERVO, MELSERVO-J4 AC Servos MELSERVO and Embedded Type Servo System Controller allow a remote attacker to cause a temporary Denial of Service condition for a certain period of time in Ethernet communication of the products by performing TCP SYN Flood attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7033?
The severity of CVE-2023-7033 is classified as critical due to insufficient resource management that may lead to denial of service.
How do I fix CVE-2023-7033?
To fix CVE-2023-7033, users should apply the latest firmware update provided by Mitsubishi Electric for affected devices.
What devices are affected by CVE-2023-7033?
CVE-2023-7033 affects various Mitsubishi Electric products including MELSEC iQ-R and iQ-L series CPU modules and various CC-Link IE TSN modules.
What can happen if CVE-2023-7033 is exploited?
Exploitation of CVE-2023-7033 can result in denial of service, impacting the functionality of the affected Ethernet devices.
Has CVE-2023-7033 been actively exploited?
As of now, there are no reported incidents of active exploitation of CVE-2023-7033.