QID 590629

Date Published: 2022-02-14

QID 590629: Mitsubishi Electric MELSEC-Q Series Ethernet Module Denial of Service (DoS) Vulnerability (ICSA-19-141-02)

AFFECTED PRODUCTS
The following MELSEC-Q series Ethernet module is affected:
QJ71E71-100 serial number 20121 and prior

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability may render the device unresponsive, requiring a physical reset of the PLC (Programmable Logic Controller).

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-19-141-02 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590629

    Software Advisories
    Advisory ID Software Component Link
    ICSA-19-141-02 URL Logo www.us-cert.gov/ics/advisories/ICSA-19-141-02