QID 591385
Date Published: 2023-04-03
QID 591385: Mitsubishi Electric MELSEC C Controller Module and MELIPC Series MI5000 Transmission Control Protocol/Internet Protocol (TCP/IP) function Multiple Vulnerabilities (2019-003)
AFFECTED PRODUCTS
Affected products and Ethernet ports are as follows.
(MELSEC-Q Series C Controller Module)
-Q24DHCCPU-V, Q24DHCCPU-VG User Ethernet port (CH1, CH2): First 5 digits of serial number are 21121 or before.
The serial number of CPU module can be checked on a rating plate on the side of the module or serial number display on the front of the module, or checked in "System monitor" of Setting/monitoring tools for the MELSEC C Controller Module.
(MELSEC iQ-R Series C Controller Module / C Intelligent Function Module)
-R12CCPU-V Ethernet port (CH1, CH2): First 2 digits of serial number are 11 or before.
The serial number of CPU module can be checked on a rating plate on the side of the module or serial number display on the front of the module, or checked in "System monitor" of CW Configurator.
-RD55UP06-V Ethernet port: First 2 digits of serial number are 08 or before.
The serial number of CPU module can be checked on a rating plate on the side of the module or serial number display on the front of the module, or checked in "System monitor" of GX Works3.
(MELIPC Series MI5000)
-MI5122-VW Ethernet port (CH1): First 2 digits of serial number are 03 or before.
The serial number of CPU module can be checked on a rating plate on the side of the module or serial number display on the front of the module, and the firmware version can be checked in "MELIPC Diagnosis" of MI Configurator.
QID Detection Logic:
This QID checks for the Vulnerable version of Mitsubishi Electric MELSEC C Controller Module and MELIPC Series MI5000 using passive scanning.
Receiving a TCP packet crafted by a remote attacker may cause service of the product to stop or a malicious program to execute
Customers are advised to refer to CERT MITIGATIONS section 2019-003 for affected packages and patching details.
CVEs related to QID 591385
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 2019-003 |
|