CVE-2022-24946

CVSS V2 High 7.8 CVSS V3 High 7.5
Description
Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V firmware versions "16" and prior, Mitsubishi Electric MELSEC-Q Series Q03UDECPU the first 5 digits of serial No. "24061" and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/10/13/20/26/50/100UDEHCPU the first 5 digits of serial No. "24061" and prior, Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/13/26UDPVCPU the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-Q Series Q12DCCPU-V all versions, Mitsubishi Electric MELSEC-Q Series Q24DHCCPU-V(G) all versions, Mitsubishi Electric MELSEC-Q Series Q24/26DHCCPU-LS all versions, Mitsubishi Electric MELSEC-L series L02/06/26CPU(-P) the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-L series L26CPU-(P)BT the first 5 digits of serial number "24051" and prior and Mitsubishi Electric MELIPC Series MI5122-VW firmware versions "05" and prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition in Ethernet communications by sending specially crafted packets. A system reset of the products is required for recovery.
Overview
  • CVE ID
  • CVE-2022-24946
  • Assigner
  • Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
  • Vulnerability Status
  • Modified
  • Published Version
  • 2022-06-15T21:15:09
  • Last Modified Date
  • 2022-08-19T23:25:31
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:o:mitsubishielectric:q03udecpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q03udecpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q04udehcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q04udehcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q04udpvcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q04udpvcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q04udvcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q04udvcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q100udehcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q100udehcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q50udehcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q50udehcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q26dhccpu-ls_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q26dhccpu-ls:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q26udehcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q26udehcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q26udpvcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q26udpvcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q26udvcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q26udvcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q20udehcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q20udehcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q13udehcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q13udehcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q13udpvcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q13udpvcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q13udvcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q13udvcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q10udehcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q10udehcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q06ccpu-v_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q06ccpu-v:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q06phcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q06phcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q06udehcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q06udehcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q06udpvcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q06udpvcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q06udvcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q06udvcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l02cpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l02cpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l02cpu-p_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l02cpu-p:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l02scpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l02scpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l02scpu-p_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l02scpu-p:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l06cpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l06cpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l06cpu-p_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l06cpu-p:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l26cpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l26cpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l26cpu-\(p\)bt_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l26cpu-\(p\)bt:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l26cpu-bt_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l26cpu-bt:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l26cpu-bt-cm_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l26cpu-bt-cm:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l26cpu-p_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l26cpu-p:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l26cpu-pbt_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l26cpu-pbt:-:*:*:*:*:*:*:* 0 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:L/Au:N/C:N/I:N/A:C
  • Access Vector
  • NETWORK
  • Access Compatibility
  • LOW
  • Authentication
  • NONE
  • Confidentiality Impact
  • NONE
  • Integrity Impact
  • NONE
  • Availability Impact
  • COMPLETE
  • Base Score
  • 7.8
  • Severity
  • HIGH
  • Exploitability Score
  • 10
  • Impact Score
  • 6.9
CVSS Version 3
  • Version
  • 3.1
  • Vector String
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • NONE
  • User Interaction
  • NONE
  • Scope
  • UNCHANGED
  • Confidentiality Impact
  • NONE
  • Availability Impact
  • HIGH
  • Base Score
  • 7.5
  • Base Severity
  • HIGH
  • Exploitability Score
  • 3.9
  • Impact Score
  • 3.6
History
Created Old Value New Value Data Type Notes
2022-06-15 22:00:07 Added to TrackCVE