CVE-2022-25163

Improper Input Validation vulnerability in Mitsubishi Electric MELSEC-Q Series QJ71E71-100 first 5 digits of serial number "24061" or prior, Mitsubishi Electric MELSEC-L series LJ71E71-100 first 5 digits of serial number "24061" or prior and Mitsubishi Electric MELSEC iQ-R Series RD81MES96N firmware version "08" or prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on the target products by sending specially crafted packets.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:mitsubishi:melsec_iq-r_rd81mes96n_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:melsec_iq-r_rd81mes96n:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:mitsubishi:melsec_qj71e71-100_firmware:*:*:*:*:*:*:*:f
cpe:2.3:h:mistubishi:melsec_qj71e71-100:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:mitsubishi:melsec_lj71e71-100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:melsec_lj71e71-100:-:*:*:*:*:*:*:*

History

17 Jun 2022, 14:26

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 10.0
v3 : 9.8
CPE cpe:2.3:o:mitsubishi:melsec_lj71e71-100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mistubishi:melsec_qj71e71-100:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishi:melsec_iq-r_rd81mes96n_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:melsec_iq-r_rd81mes96n:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishi:melsec_qj71e71-100_firmware:*:*:*:*:*:*:*:f
cpe:2.3:h:mitsubishi:melsec_lj71e71-100:-:*:*:*:*:*:*:*
CWE CWE-20
First Time Mitsubishi melsec Qj71e71-100 Firmware
Mitsubishi melsec Lj71e71-100 Firmware
Mistubishi
Mitsubishi melsec Lj71e71-100
Mitsubishi
Mitsubishi melsec Iq-r Rd81mes96n
Mistubishi melsec Qj71e71-100
Mitsubishi melsec Iq-r Rd81mes96n Firmware
References (MISC) https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-006_en.pdf - (MISC) https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-006_en.pdf - Vendor Advisory
References (MISC) https://jvn.jp/vu/JVNVU92561747/index.html - (MISC) https://jvn.jp/vu/JVNVU92561747/index.html - Third Party Advisory

02 Jun 2022, 18:34

Type Values Removed Values Added
New CVE

Information

Published : 2022-06-02 18:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-25163

Mitre link : CVE-2022-25163

CVE.ORG link : CVE-2022-25163


JSON object : View

Products Affected

mitsubishi

  • melsec_lj71e71-100_firmware
  • melsec_iq-r_rd81mes96n_firmware
  • melsec_iq-r_rd81mes96n
  • melsec_lj71e71-100
  • melsec_qj71e71-100_firmware

mistubishi

  • melsec_qj71e71-100
CWE
CWE-20

Improper Input Validation