CVE-2022-40267
Published on: Not Yet Published
Last Modified on: 04/18/2023 04:15:00 AM UTC
Certain versions of Fx5s-30mr/es from Mitsubishielectric contain the following vulnerability:
Predictable Seed in Pseudo-Random Number Generator (PRNG) vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U-xMy/z (x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 17X**** or later, and versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U-xMy/z (x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 179**** and prior, and versions 1.074 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-xMy/z (x=32,64,96, y=T, z=D,DSS)) with serial number 17X**** or later, and versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-xMy/z (x=32,64,96, y=T, z=D,DSS)) with serial number 179**** and prior, and versions 1.074 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-32MT/DS-TS versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-32MT/DSS-TS versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UJ-xMy/z (x=24,40,60, y=T,R, z=ES,ESS) versions 1.042 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UJ-xMy/ES-A (x=24,40,60, y=T,R) versions 1.043 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5S-xMy/z (x=30,40,60,80, y=T,R, z=ES,ESS) versions 1.003 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-32MR/DS-TS versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R00/01/02CPU versions 33 and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120(EN)CPU versions 66 and prior allows a remote unauthenticated attacker to access the Web server function by guessing the random numbers used for authentication from several used random numbers.
- CVE-2022-40267 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
CVSS3 Score: 9.1 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
www.mitsubishielectric.com application/pdf |
![]() | |
Mitsubishi Electric MELSEC iQ-F, iQ-R Series | CISA | www.cisa.gov text/html |
![]() |
JVNVU#99673580: 三菱電機製MELSECシリーズのWEBサーバ機能における認証回避の脆弱性 | jvn.jp text/xml |
![]() |
Related QID Numbers
- 591327 Mitsubishi Electric Remote Code Execution Vulnerability (icsa-23-017-02)
Exploit/POC from Github
Predictable Seed in Pseudo-Random Number Generator (PRNG) vulnerability in Mitsubishi Electric Corporation MELSEC iQ-…
Known Affected Configurations (CPE V2.3)
- cpe:2.3:h:mitsubishielectric:fx5s-30mr\/es:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5s-30mr\/es_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5s-30mt\/es:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5s-30mt\/ess:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5s-30mt\/ess_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5s-30mt\/es_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5s-40mr\/es:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5s-40mr\/es_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5s-40mt\/es:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5s-40mt\/ess:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5s-40mt\/ess_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5s-40mt\/es_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5s-60mr\/es:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5s-60mr\/es_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5s-60mt\/es:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5s-60mt\/ess:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5s-60mt\/ess_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5s-60mt\/es_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5s-80mr\/es:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5s-80mr\/es_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5s-80mt\/es:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5s-80mt\/ess:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5s-80mt\/ess_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5s-80mt\/es_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5u-32mt\/dss:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5u-32mt\/dss_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5u-64mt\/dss:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5u-64mt\/dss_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5u-80mt\/dss:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5u-80mt\/dss_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5u-80mt\/ess:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5u-80mt\/ess_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uc-32mr\/ds-ts:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uc-32mr\/ds-ts_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uc-32mt\/d:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uc-32mt\/ds-ts:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uc-32mt\/ds-ts_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uc-32mt\/dss:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uc-32mt\/dss-ts:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uc-32mt\/dss-ts_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uc-32mt\/dss_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uc-32mt\/d_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uc-64mt\/d:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uc-64mt\/dss:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uc-64mt\/dss_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uc-64mt\/d_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uc-96mt\/d:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uc-96mt\/dss:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uc-96mt\/dss_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uc-96mt\/d_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uj-24mr\/es:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uj-24mr\/es-a:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uj-24mr\/es-a_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uj-24mr\/es_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uj-24mt\/es:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uj-24mt\/es-a:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uj-24mt\/es-a_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uj-24mt\/ess:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uj-24mt\/ess_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uj-24mt\/es_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uj-40mr\/es:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uj-40mr\/es-a:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uj-40mr\/es-a_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uj-40mr\/es_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uj-40mt\/es:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uj-40mt\/es-a:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uj-40mt\/es-a_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uj-40mt\/ess:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uj-40mt\/ess_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uj-40mt\/es_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uj-60mr\/es:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uj-60mr\/es-a:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uj-60mr\/es-a_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uj-60mr\/es_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uj-60mt\/es:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uj-60mt\/es-a:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uj-60mt\/es-a_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:fx5uj-60mt\/ess:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uj-60mt\/ess_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:fx5uj-60mt\/es_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:r00cpu:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:r00cpu_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:r01cpu:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:r01cpu_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:r02cpu:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:r02cpu_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:r04cpu:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:r04cpu_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:r04encpu:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:r04encpu_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:r08cpu:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:r08cpu_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:r08encpu:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:r08encpu_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:r120cpu:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:r120cpu_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:r120encpu:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:r120encpu_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:r16cpu:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:r16cpu_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:r16encpu:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:r16encpu_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:r32cpu:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:r32cpu_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:r32encpu:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:r32encpu_firmware:-:*:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-40267 | 2023-01-20 08:39:22 |