QID 591254

Date Published: 2023-01-06

QID 591254: Mitsubishi Electric MELSEC iQ-R, iQ-L Series and MELIPC Series Improper Resource Shutdown or Release Vulnerability (ICSA-22-356-03, 2022-018)

AFFECTED PRODUCTS
MELSEC iQ-R Series R00/01/02CPU: Firmware versions "32" and prior.
MELSEC iQ-R Series R04/08/16/32/120(EN)CPU: Firmware versions "65" and prior.
MELSEC iQ-R Series R08/16/32/120SFCPU: All versions.
MELSEC iQ-R Series R12CCPU-V: All versions.
MELSEC iQ-L Series L04/08/16/32HCPU: All versions.
MELIPC Series MI5122-VW: All versions.

QID Detection Logic:
This QID checks for the Vulnerable version of Mitsubishi Electric MELSEC iQ-R, iQ-L Series and MELIPC Series using passive scanning

Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service condition in the module's ethernet communication.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-22-356-03 or Mitsubishi Electric MITIGATIONS section 2022-018 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591254

    Software Advisories
    Advisory ID Software Component Link
    2022-018 URL Logo www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-018_en.pdf
    ICSA-22-356-03 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-356-03