QID 590636

Date Published: 2022-02-14

QID 590636: Mitsubishi Electric MELSEC-Q Series Ethernet Interface Module Multiple Vulnerabilities (ICSA-16-336-03)

AFFECTED PRODUCTS
The following MELSEC-Q series versions are affected:
QJ71E71-100, all versions,
QJ71E71-B5, all versions, and
QJ71E71-B2, all versions.

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities may allow an attacker to intercept weakly encrypted passwords and allow an unauthenticated remote attacker to cause a denial of service on the affected system.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-16-336-03 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590636

    Software Advisories
    Advisory ID Software Component Link
    ICSA-16-336-03 URL Logo www.us-cert.gov/ics/advisories/ICSA-16-336-03