QID 591225

Date Published: 2022-12-09

QID 591225: Mitsubishi Electric MELSEC iQ-R Series Improper Input Validation Vulnerability (icsa-22-335-01)

AFFECTED PRODUCTS
The following Mitsubishi Electric MELSEC iQ-R Series products are affected: RJ71EN71: Firmware version "65" and prior
R04/08/16/32/120ENCPU: Network part firmware version "65" and prior

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to cause a denial-of-service condition on a target product by sending specially crafted packets.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Low - 0 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section icsa-22-335-01 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591225

    Software Advisories
    Advisory ID Software Component Link
    icsa-22-335-01 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-335-01