QID 590883

Date Published: 2022-06-30

QID 590883: Mitsubishi Electric MELSEC-Q/L Series Ethernet Interface Module and MELSEC iQ-R Series MES Interface Module Vulnerability (2022-006)

AFFECTED PRODUCTS
MELSEC-Q Series QJ71E71-100 First 5 digits of serial number 24061 or prior
MELSEC-L Series LJ71E71-100 First 5 digits of serial number 24061 or prior.
MELSEC iQ-R Series RD81MES96N Firmware version 08 or prior

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

A remote unauthenticated attacker may cause a DoS condition or execute malicious code on target products by sending specially crafted packets. A system reset is required for recovery from a denial of service (DoS) condition and remote code execution.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as Medium - 5.1 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section 2022-006 for affected packages and patching details.

    CVEs related to QID 590883

    Software Advisories
    Advisory ID Software Component Link
    2022-006 URL Logo www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-006_en.pdf