PT-2024-2052 · Mitsubishi · Melsec Iq-R Ethernet Interface Module+23
Published
2024-02-26
·
Updated
2025-01-16
·
CVE-2023-7033
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
MELSEC iQ-R series CPU module (affected versions not specified)
MELSEC iQ-L series CPU module (affected versions not specified)
MELSEC iQ-R Ethernet Interface Module (affected versions not specified)
MELSEC iQ-R CC-Link IE TSN Master/Local Module (affected versions not specified)
CC-Link IE TSN Remote I/O Module (affected versions not specified)
CC-Link IE TSN Analog-Digital Converter Module (affected versions not specified)
CC-Link IE TSN Digital-Analog Converter Module (affected versions not specified)
CC-Link IE TSN - CC-Link IE Field Network Bridge Module (affected versions not specified)
CC-Link IE TSN - AnyWireASLINK Bridge Module (affected versions not specified)
CC-Link IE TSN FPGA Module (affected versions not specified)
CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY (affected versions not specified)
MELSEC iQ-R Motion Module (affected versions not specified)
MELSEC iQ-L Motion Module (affected versions not specified)
MELSEC iQ-F FX5 Motion Module (affected versions not specified)
MELSEC iQ-F Series CPU module (affected versions not specified)
MELSEC iQ-F Series Ethernet module (affected versions not specified)
MELSEC iQ-F Series Ethernet/IP module (affected versions not specified)
MELSEC iQ-F Series OPC UA Module (affected versions not specified)
MELSEC iQ-F Series CC-Link IE TSN master/local module (affected versions not specified)
GOT2000 Series CC-Link IE TSN Communication Unit (affected versions not specified)
FR-A800-E series inverters (affected versions not specified)
FR-F800-E series inverters (affected versions not specified)
FR-E800-E series inverters (affected versions not specified)
INVERTER CC-Link IE TSN Plug-in option (affected versions not specified)
INVERTER CC-Link IE TSN Safety Plug-in option (affected versions not specified)
INVERTER CC-Link IE TSN communication function built-in type (affected versions not specified)
MR-J5 series AC Servos MELSERVO (affected versions not specified)
MR-JET series AC Servos MELSERVO (affected versions not specified)
MR-MD333G series AC Servos MELSERVO (affected versions not specified)
MR-JE series AC Servos MELSERVO (affected versions not specified)
MELSERVO-J4 AC Servos MELSERVO (affected versions not specified)
Embedded Type Servo System Controller (affected versions not specified)
Description
The issue is related to an Insufficient Resource Pool vulnerability in the Ethernet function of various Mitsubishi Electric Corporation products. This vulnerability allows a remote attacker to cause a temporary Denial of Service condition for a certain period of time in Ethernet communication of the products by performing a TCP SYN Flood attack.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cc-Link Ie Tsn - Anywireaslink Bridge Module
Cc-Link Ie Tsn - Cc-Link Ie Field Network Bridge Module
Cc-Link Ie Tsn Digital-Analog Converter Module
Cc-Link Ie Tsn Fpga Module
Cc-Link Ie Tsn Remote I/O Module
Cc-Link Ie Tsn Remote Station Communication Lsi Cp620 With Gbe-Phy
Embedded Type Servo System Controller
Fr-A800-E Series Inverters
Fr-E800-E Series Inverters
Got2000 Series Cc-Link Ie Tsn Communication Unit
Inverter Cc-Link Ie Tsn Plug-In Option
Inverter Cc-Link Ie Tsn Communication Function Built-In Type
Melsec Iq-F Fx5 Motion Module
Melsec Iq-F Series Cc-Link Ie Tsn Master/Local Module
Melsec Iq-F Series Cpu Module
Melsec Iq-F Series Ethernet/Ip Module
Melsec Iq-L Motion Module
Melsec Iq-R Series Cpu Modules
Melsec Iq-R Ethernet Interface Module
Melservo-J4 Ac Servos Melservo
Mr-J5 Series Ac Servos Melservo
Mr-Je Series Ac Servos Melservo
Mr-Jet Series Ac Servos Melservo
Mr-Md333G Series Ac Servos Melservo