PT-2021-7078 · Mitsubishi · Melsec Iq-F Series Fx5Uc-32Mr/Ds-Ts+2
Anton Dorfman
·
Published
2021-12-15
·
Updated
2022-06-06
·
CVE-2022-25161
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z versions prior to 1.270
Mitsubishi Electric MELSEC iQ-F series FX5UC-xMy/z versions prior to 1.270
Mitsubishi Electric MELSEC iQ-F series FX5UC-32MT/DS-TS versions prior to 1.270
Mitsubishi Electric MELSEC iQ-F series FX5UC-32MT/DSS-TS versions prior to 1.270
Mitsubishi Electric MELSEC iQ-F series FX5UC-32MR/DS-TS versions prior to 1.270
Mitsubishi Electric MELSEC iQ-F series FX5UJ-xMy/z versions prior to 1.030
Mitsubishi Electric MELSEC iQ-F series FX5UJ-xMy/ES-A versions prior to 1.031
Mitsubishi Electric MELSEC iQ-F series FX5S-xMy/z version 1.000
Description
The issue is related to improper input validation, allowing a remote unauthenticated attacker to cause a DoS condition for the product's program execution or communication by sending specially crafted packets. System reset of the product is required for recovery.
Recommendations
For Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z versions prior to 1.270, update to version 1.270 or later.
For Mitsubishi Electric MELSEC iQ-F series FX5UC-xMy/z versions prior to 1.270, update to version 1.270 or later.
For Mitsubishi Electric MELSEC iQ-F series FX5UC-32MT/DS-TS versions prior to 1.270, update to version 1.270 or later.
For Mitsubishi Electric MELSEC iQ-F series FX5UC-32MT/DSS-TS versions prior to 1.270, update to version 1.270 or later.
For Mitsubishi Electric MELSEC iQ-F series FX5UC-32MR/DS-TS versions prior to 1.270, update to version 1.270 or later.
For Mitsubishi Electric MELSEC iQ-F series FX5UJ-xMy/z versions prior to 1.030, update to version 1.030 or later.
For Mitsubishi Electric MELSEC iQ-F series FX5UJ-xMy/ES-A versions prior to 1.031, update to version 1.031 or later.
For Mitsubishi Electric MELSEC iQ-F series FX5S-xMy/z version 1.000, update to a version later than 1.000.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Melsec Iq-F Series Fx5S-Xmy/Z
Melsec Iq-F Series Fx5Uc-32Mr/Ds-Ts
Melsec Iq-F Series Fx5Uj-Xmy/Es-A