CVE-2022-33324— Denial-of-Service Vulnerability in Ethernet port of MELSEC iQ-R, iQ-L Series and MELIPC Series
Quick assessment
Affected
Mitsubishi Electric Corporation MELSEC iQ-R Series R00CPU
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.
Mitsubishi Electric MELSEC iQ-R series和Mitsubishi Electric MELSEC iQ-L Series都是日本三菱电机(Mitsubishi Electric)公司的产品。Mitsubishi Electric MELSEC iQ-R series是一款可编程逻辑控制器。Mitsubishi Electric MELSEC iQ-L Series是一系列可编程逻辑控制器。 Mitsubishi Electric MELSEC iQ-R、iQ-L Seri
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Denial-of-Service Vulnerability in Ethernet port of MELSEC iQ-R, iQ-L Series and MELIPC Series
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series R00/01/02CPU Firmware versions "32" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120(EN)CPU Firmware versions "65" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R08/16/32/120SFCPU Firmware versions "29" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R08/16/32/120PSFCPU Firmware versions "08" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R12CCPU-V Firmware versions "17" and prior, Mitsubishi Electric Corporation MELSEC iQ-L Series L04/08/16/32HCPU Firmware versions "05" and prior and Mitsubishi Electric Corporation MELIPC Series MI5122-VW Firmware versions "07" and prior allows a remote unauthenticated attacker to cause a Denial of Service condition in Ethernet communication on the module by sending specially crafted packets. A system reset of the module is required for recovery.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
不恰当的资源关闭或释放
Source: CVE Program / CVE List V5
Vulnerability Title
Mitsubishi Electric MELSEC iQ-R、iQ-L Series 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mitsubishi Electric MELSEC iQ-R series和Mitsubishi Electric MELSEC iQ-L Series都是日本三菱电机(Mitsubishi Electric)公司的产品。Mitsubishi Electric MELSEC iQ-R series是一款可编程逻辑控制器。Mitsubishi Electric MELSEC iQ-L Series是一系列可编程逻辑控制器。 Mitsubishi Electric MELSEC iQ-R、iQ-L Seri
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)