CVE-2022-24946

high-risk
Published 2022-06-15

Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V firmware versions "16" and prior, Mitsubishi Electric MELSEC-Q Series Q03UDECPU the first 5 digits of serial No. "24061" and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/10/13/20/26/50/100UDEHCPU the first 5 digits of serial No. "24061" and prior, Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/13/26UDPVCPU the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-Q Series Q12DCCPU-V all versions, Mitsubishi Electric MELSEC-Q Series Q24DHCCPU-V(G) all versions, Mitsubishi Electric MELSEC-Q Series Q24/26DHCCPU-LS all versions, Mitsubishi Electric MELSEC-L series L02/06/26CPU(-P) the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-L series L26CPU-(P)BT the first 5 digits of serial number "24051" and prior and Mitsubishi Electric MELIPC Series MI5122-VW firmware versions "05" and prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition in Ethernet communications by sending specially crafted packets. A system reset of the products is required for recovery.

Do I need to act?

-
0.44% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10 High
NETWORK / LOW complexity

Affected Products (20)

Q03Udecpu Firmware
Q04Udehcpu Firmware
Q04Udpvcpu Firmware
Q04Udvcpu Firmware
Q100Udehcpu Firmware
Q50Udehcpu Firmware
Q26Dhccpu-Ls Firmware
Q26Udehcpu Firmware
Q26Udpvcpu Firmware
Q26Udvcpu Firmware
Q20Udehcpu Firmware
Q13Udehcpu Firmware
Q13Udpvcpu Firmware
Q13Udvcpu Firmware
Q10Udehcpu Firmware
Q06Ccpu-V Firmware
Q06Phcpu Firmware
Q06Udehcpu Firmware
Q06Udpvcpu Firmware
Q06Udvcpu Firmware

Affected Vendors

51
/ 100
high-risk
Severity 26/34 · High
Exploitability 2/34 · Minimal
Exposure 23/34 · High