ICSA-22-172-01: Mitsubishi electric melsec iq-r r12ccpu-v vulnerability
Affected Software
28 affected components
: Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V CPU Firmware: Version 16 and prior
: Mitsubishi Electric MELSEC Q Series Q03UDECPU: Versions with the first 5 digits of serial number 24061 and prior
: Mitsubishi Electric MELSEC Q Series Q04UDECPU: Versions with the first 5 digits of serial number 24061 and prior
: Mitsubishi Electric MELSEC Q Series Q06UDECPU: Versions with the first 5 digits of serial number 24061 and prior
: Mitsubishi Electric MELSEC Q Series Q10UDECPU: Versions with the first 5 digits of serial number 24061 and prior
: Mitsubishi Electric MELSEC Q Series Q13UDECPU: Versions with the first 5 digits of serial number 24061 and prior
: Mitsubishi Electric MELSEC Q Series Q20UDECPU: Versions with the first 5 digits of serial number 24061 and prior
: Mitsubishi Electric MELSEC Q Series Q26UDECPU: Versions with the first 5 digits of serial number 24061 and prior
: Mitsubishi Electric MELSEC Q Series Q50UDECPU: Versions with the first 5 digits of serial number 24061 and prior
: Mitsubishi Electric MELSEC Q Series Q100UDECPU: Versions with the first 5 digits of serial number 24061 and prior
: Mitsubishi Electric MELSEC Q Series Q03UDVCPU: Versions with the first 5 digits of serial number 24051 and prior
: Mitsubishi Electric MELSEC Q Series Q04UDVCPU: Versions with the first 5 digits of serial number 24051 and prior
: Mitsubishi Electric MELSEC Q Series Q06UDVCPU: Versions with the first 5 digits of serial number 24051 and prior
: Mitsubishi Electric MELSEC Q Series Q13UDVCPU: Versions with the first 5 digits of serial number 24051 and prior
: Mitsubishi Electric MELSEC Q Series Q26UDVCPU: Versions with the first 5 digits of serial number 24051 and prior
: Mitsubishi Electric MELSEC Q Series Q04UDPVCPU: Versions with the first 5 digits of serial number 24051 and prior
: Mitsubishi Electric MELSEC Q Series Q06UDPVCPU: Versions with the first 5 digits of serial number 24051 and prior
: Mitsubishi Electric MELSEC Q Series Q13UDPVCPU: Versions with the first 5 digits of serial number 24051 and prior
: Mitsubishi Electric MELSEC Q Series Q26UDPVCPU: Versions with the first 5 digits of serial number 24051 and prior
: Mitsubishi Electric MELSEC Q Series Q12DCCPU-V: Versions with the first 5 digits of serial number 25061 and prior
: Mitsubishi Electric MELSEC Q Series Q24DHCCPU-V(G): Versions with the first 5 digits of serial number 25061 and prior
: Mitsubishi Electric MELSEC Q Series Q24DHCCPU-LS: Versions with the first 5 digits of serial number 25061 and prior
: Mitsubishi Electric MELSEC Q Series Q26DHCCPU-LS: Versions with the first 5 digits of serial number 25061 and prior
: Mitsubishi Electric MELSEC L Series L02CPU(-P): Versions with the first 5 digits of serial number 24051 and prior
: Mitsubishi Electric MELSEC L Series L06CPU(-P): Versions with the first 5 digits of serial number 24051 and prior
: Mitsubishi Electric MELSEC L Series L26CPU(-P): Versions with the first 5 digits of serial number 24051 and prior
: Mitsubishi Electric MELSEC L Series L26CPU-(P)BT: Versions with the first 5 digits of serial number 24051 and prior
: Mitsubishi Electric MELIPC Series MI5122-VW CPU Firmware: Version 05 and prior
Event History
Feb 23, 2025
Advisory Published
01:15 PM
Frequently Asked Questions
1
What is the severity of ICSA-22-172-01?
The severity of ICSA-22-172-01 is rated as high due to potential remote code execution vulnerabilities.
2
How do I fix ICSA-22-172-01?
To fix ICSA-22-172-01, update the firmware to the latest version provided by Mitsubishi Electric.
3
What products are affected by ICSA-22-172-01?
ICSA-22-172-01 affects Mitsubishi Electric MELSEC iQ-R Series and MELSEC Q Series CPUs with specific firmware versions and serial numbers.
4
Are there mitigations available for ICSA-22-172-01?
While immediate fixes require firmware updates, network segmentation can help mitigate exposure until updates are applied.
5
What is the impact of ICSA-22-172-01 if exploited?
If ICSA-22-172-01 is exploited, it can allow remote attackers to execute arbitrary code on the affected devices.