QID 590633
Date Published: 2022-02-14
QID 590633: Mitsubishi Electric MELSEC iQ-R, Q and L Series (Update A) Denial of Service (DoS) Vulnerability (ICSA-20-303-01)
AFFECTED PRODUCTS
The following versions of MELSEC iQ-R Series are affected:
R 00/01/02 CPU, firmware Versions 20 and earlier
R 04/08/16/32/120 (EN) CPU, firmware Versions 52 and earlier
R 08/16/32/120 SFCPU, firmware Versions 22 and earlier
R 08/16/32/120 PCPU, firmware Versions 25 and earlier
R 08/16/32/120 PSFCPU, all versions
R 16/32/64 MTCPU, all versions
The following versions of MELSEC Q Series are affected:
Q03 UDECPU, Q 04/06/10/13/20/26/50/100 UDEHCPU, serial number 22081 and earlier
Q 03/04/06/13/26 UDVCPU, serial number 22031 and earlier
Q 04/06/13/26 UDPVCPU, serial number 22031 and earlier
Q 172/173 DCPU-S1, all versions
Q 172/173 DSCPU, all versions
Q 170 MCPU, all versions
Q 170 MSCPU (-S1), all versions
MR-MQ100, all versions
The following versions of MELSEC L Series are affected:
L 02/06/26 CPU (-P), L 26 CPU - (P) BT, all versions
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
Successful exploitation of this vulnerability could cause a denial-of-service condition in the Ethernet port on the CPU module.
Customers are advised to refer to CERT MITIGATIONS section ICSA-20-303-01 for affected packages and patching details.
- ICSA-20-303-01 -
www.us-cert.gov/ics/advisories/ICSA-20-303-01
CVEs related to QID 590633
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-20-303-01 |
|