CVE-2022-25163

Improper Input Validation vulnerability in Mitsubishi Electric MELSEC-Q Series QJ71E71-100 first 5 digits of serial number "24061" or prior, Mitsubishi Electric MELSEC-L series LJ71E71-100 first 5 digits of serial number "24061" or prior and Mitsubishi Electric MELSEC iQ-R Series RD81MES96N firmware version "08" or prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on the target products by sending specially crafted packets.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:mitsubishi:melsec_iq-r_rd81mes96n_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:melsec_iq-r_rd81mes96n:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:mitsubishi:melsec_qj71e71-100_firmware:*:*:*:*:*:*:*:f
cpe:2.3:h:mistubishi:melsec_qj71e71-100:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:mitsubishi:melsec_lj71e71-100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:melsec_lj71e71-100:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:51

Type Values Removed Values Added
References () https://jvn.jp/vu/JVNVU92561747/index.html - Third Party Advisory () https://jvn.jp/vu/JVNVU92561747/index.html - Third Party Advisory
References () https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-006_en.pdf - Vendor Advisory () https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-006_en.pdf - Vendor Advisory

Information

Published : 2022-06-02 18:15

Updated : 2024-11-21 06:51


NVD link : CVE-2022-25163

Mitre link : CVE-2022-25163

CVE.ORG link : CVE-2022-25163


JSON object : View

Products Affected

mitsubishi

  • melsec_lj71e71-100_firmware
  • melsec_iq-r_rd81mes96n
  • melsec_lj71e71-100
  • melsec_iq-r_rd81mes96n_firmware
  • melsec_qj71e71-100_firmware

mistubishi

  • melsec_qj71e71-100
CWE
CWE-20

Improper Input Validation