QID 590865

Date Published: 2022-06-23

QID 590865: Mitsubishi Electric MELSEC-Q Series C Controller Module Vulnerability (ICSA-22-102-02) (2022-001)

AFFECTED PRODUCTS
The following versions of MELSEC-Q Series C Controller Module using Wind River VxWorks Version 6.4 are affected:
Module Q12DCCPU-V: First 5 digits of serial number 24031 and prior

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability could cause a denial-of-service condition or allow remote code execution.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-22-102-02 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590865

    Software Advisories
    Advisory ID Software Component Link
    ICSA-22-102-02 URL Logo www.us-cert.gov/ics/advisories/ICSA-22-102-02