HIGH · 7.5

CVE-2022-24946

Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V firmware versions "16" and prior, Mitsubishi Electric MELSEC-Q Series Q03UDECPU the first 5 digits of serial...

Vulnerability Description

Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V firmware versions "16" and prior, Mitsubishi Electric MELSEC-Q Series Q03UDECPU the first 5 digits of serial No. "24061" and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/10/13/20/26/50/100UDEHCPU the first 5 digits of serial No. "24061" and prior, Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/13/26UDPVCPU the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-Q Series Q12DCCPU-V all versions, Mitsubishi Electric MELSEC-Q Series Q24DHCCPU-V(G) all versions, Mitsubishi Electric MELSEC-Q Series Q24/26DHCCPU-LS all versions, Mitsubishi Electric MELSEC-L series L02/06/26CPU(-P) the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-L series L26CPU-(P)BT the first 5 digits of serial number "24051" and prior and Mitsubishi Electric MELIPC Series MI5122-VW firmware versions "05" and prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition in Ethernet communications by sending specially crafted packets. A system reset of the products is required for recovery.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
MitsubishielectricQ03Udecpu Firmware-
MitsubishielectricQ03Udecpu-
MitsubishielectricQ04Udehcpu Firmware-
MitsubishielectricQ04Udehcpu-
MitsubishielectricQ04Udpvcpu Firmware-
MitsubishielectricQ04Udpvcpu-
MitsubishielectricQ04Udvcpu Firmware-
MitsubishielectricQ04Udvcpu-
MitsubishielectricQ100Udehcpu Firmware-
MitsubishielectricQ100Udehcpu-
MitsubishielectricQ50Udehcpu Firmware-
MitsubishielectricQ50Udehcpu-
MitsubishielectricQ26Dhccpu-Ls Firmware-
MitsubishielectricQ26Dhccpu-Ls-
MitsubishielectricQ26Udehcpu Firmware-
MitsubishielectricQ26Udehcpu-
MitsubishielectricQ26Udpvcpu Firmware-
MitsubishielectricQ26Udpvcpu-
MitsubishielectricQ26Udvcpu Firmware-
MitsubishielectricQ26Udvcpu-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-24946?

CVE-2022-24946 is a vulnerability with a CVSS score of 7.5 (HIGH). Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V firmware versions "16" and prior, Mitsubishi Electric MELSEC-Q Series Q03UDECPU the first 5 digits of serial...

How severe is CVE-2022-24946?

CVE-2022-24946 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-24946?

Check the references section above for vendor advisories and patch information. Affected products include: Mitsubishielectric Q03Udecpu Firmware, Mitsubishielectric Q03Udecpu, Mitsubishielectric Q04Udehcpu Firmware, Mitsubishielectric Q04Udehcpu, Mitsubishielectric Q04Udpvcpu Firmware.