QID 590631

Date Published: 2022-02-14

QID 590631: Mitsubishi Electric MELSEC iQ-R Series (Update C) Denial of Service (DoS)Vulnerability (ICSA-20-324-05)

AFFECTED PRODUCTS
Mitsubishi Electric reports the vulnerability affects the following MELSEC iQ-R series CPU module products:
R00/01/02CPU firmware Versions 19 and earlier
R04/08/16/32/120(EN)CPU firmware Versions 51 and earlier
R08/16/32/120SFCPU firmware Versions 22 and earlier
R08/16/32/120PCPU firmware Versions 25 and earlier
R08/16/32/120PSFCPU firmware Versions 06 and earlier
RJ71EN71 firmware Versions 47 and earlier
RJ71GF11-T2 firmware Versions 47 and earlier
RJ72GF15-T2 firmware Versions 07 and earlier
RJ71GP21-SX firmware Versions 47 and earlier
RJ71GP21S-SX firmware Versions 47 and earlier
RJ71C24(-R2/R4) all versions
RJ71GN11-T2 firmware Versions 11 and earlier

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability could cause a denial-of-service condition for the affected product.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-20-324-05 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590631

    Software Advisories
    Advisory ID Software Component Link
    ICSA-20-324-05 URL Logo www.us-cert.gov/ics/advisories/ICSA-20-324-05