CVE-2023-7033: Medium severity Mitsubishi Electric MELSEC iQ-R series CPU module vulnerability

Published Feb 27, 2024
·
Updated

Insufficient Resource Pool vulnerability in Ethernet function of Mitsubishi Electric Corporation MELSEC iQ-R series CPU module, MELSEC iQ-L series CPU module, MELSEC iQ-R Ethernet Interface Module, MELSEC iQ-R CC-Link IE TSN Master/Local Module, CC-Link IE TSN Remote I/O Module, CC-Link IE TSN Analog-Digital Converter Module, CC-Link IE TSN Digital-Analog Converter Module, CC-Link IE TSN - CC-Link IE Field Network Bridge Module, CC-Link IE TSN - AnyWireASLINK Bridge Module, CC-Link IE TSN FPGA Module, CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY, MELSEC iQ-R Motion Module, MELSEC iQ-L Motion Module, MELSEC iQ-F FX5 Motion Module, MELSEC iQ-F Series CPU module, MELSEC iQ-F Series Ethernet module, MELSEC iQ-F Series Ethernet/IP module, MELSEC iQ-F Series OPC UA Module, MELSEC iQ-F Series CC-Link IE TSN master/local module, GOT2000 Series CC-Link IE TSN Communication Unit, FR-A800-E series inverters, FR-F800-E series inverters, FR-E800-E series inverters, INVERTER CC-Link IE TSN Plug-in option, INVERTER CC-Link IE TSN Safety Plug-in option, INVERTER CC-Link IE TSN communication function built-in type, MR-J5 series AC Servos MELSERVO, MR-JET series AC Servos MELSERVO, MR-MD333G series AC Servos MELSERVO, MR-JE series AC Servos MELSERVO, MELSERVO-J4 AC Servos MELSERVO and Embedded Type Servo System Controller allow a remote attacker to cause a temporary Denial of Service condition for a certain period of time in Ethernet communication of the products by performing TCP SYN Flood attack.

Affected Software

32 affected components
Mitsubishi Electric MELSEC iQ-R series CPU module
Mitsubishi Electric MELSEC iQ-L series CPU module
Mitsubishi Electric MELSEC iQ-R Ethernet Interface Module
Mitsubishi Electric MELSEC iQ-R CC-Link IE TSN Master/Local Module
Mitsubishi Electric CC-Link IE TSN Remote I/O Module
Mitsubishi Electric CC-Link IE TSN Analog-Digital Converter module
Mitsubishi Electric CC-Link IE TSN Digital-Analog Converter Module
Mitsubishi Electric CC-Link IE TSN - CC-Link IE Field Network Bridge Module
Mitsubishi Electric CC-Link IE TSN - AnyWireASLINK Bridge Module
Mitsubishi Electric CC-Link IE TSN FPGA module
Mitsubishi Electric CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY
Mitsubishi Electric MELSEC iQ-R Motion Module
Mitsubishi Electric MELSEC iQ-L Motion Module
Mitsubishi Electric MELSEC iQ-F FX5 Motion Module
Mitsubishi Electric MELSEC iQ-F Series CPU Module
Mitsubishi Electric MELSEC iQ-F Series Ethernet module
Mitsubishi Electric MELSEC iQ-F Series Ethernet/IP module
Mitsubishi Electric MELSEC iQ-F Series OPC UA Module
Mitsubishi Electric MELSEC iQ-F Series CC-Link IE TSN master/local module
Mitsubishi Electric GOT2000 Series CC-Link IE TSN Communication Unit
Mitsubishi Electric FR-A800-E series inverters
Mitsubishi Electric FR-F800-E series inverters
Mitsubishi Electric FR-E800-E series inverters
Mitsubishi Electric INVERTER CC-Link IE TSN Plug-in option
Mitsubishi Electric INVERTER CC-Link IE TSN Safety Plug-in option
Mitsubishi Electric INVERTER CC-Link IE TSN communication function built-in type
Mitsubishi Electric MR-J5 series AC Servos MELSERVO
Mitsubishi Electric MR-JET series AC Servos MELSERVO
Mitsubishi Electric MR-MD333G series AC Servos MELSERVO
Mitsubishi Electric MR-JE series AC Servos MELSERVO
Mitsubishi Electric MELSERVO-J4 AC Servos MELSERVO
Mitsubishi Electric Embedded Type Servo System Controller

Event History

Feb 27, 2024
CVE Published
via MITRE·03:47 AM
Data Sourced
via MITRE·03:47 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-7033?

The severity of CVE-2023-7033 is classified as critical due to insufficient resource management that may lead to denial of service.

2

How do I fix CVE-2023-7033?

To fix CVE-2023-7033, users should apply the latest firmware update provided by Mitsubishi Electric for affected devices.

3

What devices are affected by CVE-2023-7033?

CVE-2023-7033 affects various Mitsubishi Electric products including MELSEC iQ-R and iQ-L series CPU modules and various CC-Link IE TSN modules.

4

What can happen if CVE-2023-7033 is exploited?

Exploitation of CVE-2023-7033 can result in denial of service, impacting the functionality of the affected Ethernet devices.

5

Has CVE-2023-7033 been actively exploited?

As of now, there are no reported incidents of active exploitation of CVE-2023-7033.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203