Vulnerability Description
Multiple Mitsubishi Electric products are vulnerable to impersonations of a legitimate device by a malicious actor, which may allow an attacker to remotely execute arbitrary commands.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mitsubishielectric | Qj71Mes96 Firmware | All versions |
| Mitsubishielectric | Qj71Mes96 | - |
| Mitsubishielectric | Qj71Ws96 Firmware | All versions |
| Mitsubishielectric | Qj71Ws96 | - |
| Mitsubishielectric | Q06Ccpu-V Firmware | All versions |
| Mitsubishielectric | Q06Ccpu-V | - |
| Mitsubishielectric | Q24Dhccpu-V Firmware | All versions |
| Mitsubishielectric | Q24Dhccpu-V | - |
| Mitsubishielectric | Q24Dhccpu-Vg Firmware | All versions |
| Mitsubishielectric | Q24Dhccpu-Vg | - |
| Mitsubishielectric | R12Ccpu-V Firmware | All versions |
| Mitsubishielectric | R12Ccpu-V | - |
| Mitsubishielectric | Rd55Up06-V Firmware | All versions |
| Mitsubishielectric | Rd55Up06-V | - |
| Mitsubishielectric | Rd55Up12-V Firmware | All versions |
| Mitsubishielectric | Rd55Up12-V | - |
| Mitsubishielectric | Rj71Gn11-T2 Firmware | All versions |
| Mitsubishielectric | Rj71Gn11-T2 | - |
| Mitsubishielectric | Rj71En71 Firmware | All versions |
| Mitsubishielectric | Rj71En71 | - |
Related Weaknesses (CWE)
References
- https://us-cert.cisa.gov/ics/advisories/icsa-20-245-01Third Party AdvisoryUS Government Resource
- https://us-cert.cisa.gov/ics/advisories/icsa-20-245-01Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2020-16226?
CVE-2020-16226 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Multiple Mitsubishi Electric products are vulnerable to impersonations of a legitimate device by a malicious actor, which may allow an attacker to remotely execute arbitrary commands.
How severe is CVE-2020-16226?
CVE-2020-16226 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-16226?
Check the references section above for vendor advisories and patch information. Affected products include: Mitsubishielectric Qj71Mes96 Firmware, Mitsubishielectric Qj71Mes96, Mitsubishielectric Qj71Ws96 Firmware, Mitsubishielectric Qj71Ws96, Mitsubishielectric Q06Ccpu-V Firmware.