QID 591184

Date Published: 2022-11-18

QID 591184: Mitsubishi Electric Multiple Factory Automation Products (Update C) Multiple Vulnerabilities (ICSA-22-221-01)

AFFECTED PRODUCTS
The following version of GT SoftGOT2000 is affected:
CC-Link IE TSN Industrial Managed Switch (NZ2MHG-TSNT8F2, NZ2MHG-TSNT4): Version 03 and prior [affected by CVE-2022-0778 only]
MELSEC iQ-R Series OPC UA Server Module (RD81OPC96): Version 08 and prior [affected by CVE-2022-0778 only]

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities could create a denial-of-service condition or enable arbitrary code execution.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section icsa-22-221-01 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591184

    Software Advisories
    Advisory ID Software Component Link
    icsa-22-221-01 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-221-01