CVE-2022-33323
Summary
| CVE | CVE-2022-33323 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-02 06:15:00 UTC |
| Updated | 2023-07-21 19:22:00 UTC |
| Description | Active Debug Code vulnerability in robot controller of Mitsubishi Electric Corporation industrial robot MELFA SD/SQ Series and MELFA F-Series allows a remote unauthenticated attacker to gain unauthorized access by authentication bypass through an unauthorized telnet login. As for the affected model names, controller types and firmware versions, see the Mitsubishi Electric's advisory which is listed in [References] section. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Mitsubishi Electric MELFA SD/SQ series and F-series Robot Controllers | CISA | MISC | www.cisa.gov | |
| JVNVU#94588481: 三菱電機製MELFA SD/SQシリーズおよびFシリーズのロボットコントローラにおける認証回避の脆弱性 | MISC | jvn.jp | |
| www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-020_en.pdf | MISC | www.mitsubishielectric.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.