Denial-of-Service and Remote Code Execution Vulnerability in MELSEC Series CPU module
CVE-2023-1424
Key Information:
- Status
- Vendor
- CVE Published:
- 24 May 2023
Summary
A buffer overflow vulnerability exists in Mitsubishi Electric's MELSEC iQ-F and iQ-R Series CPU modules, which allows a remote unauthorized attacker to exploit it by sending specially crafted network packets. This vulnerability may enable an attacker to create a denial of service condition or to execute arbitrary code on the affected devices, necessitating a system reset for recovery. Users of these CPU modules must take immediate action to secure their systems against potential exploitation.
Affected Version(s)
MELSEC iQ-F Series FX5U-32MR/DS Serial number 17X**** or later, versions from 1.220 to 1.281
MELSEC iQ-F Series FX5U-32MR/ES Serial number 17X**** or later, versions from 1.220 to 1.281
MELSEC iQ-F Series FX5U-32MT/DS Serial number 17X**** or later, versions from 1.220 to 1.281
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved