CVE-2022-33324

moderate-risk
Published 2022-12-23

Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series R00/01/02CPU Firmware versions "32" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120(EN)CPU Firmware versions "65" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R08/16/32/120SFCPU Firmware versions "29" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R08/16/32/120PSFCPU Firmware versions "08" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R12CCPU-V Firmware versions "17" and prior, Mitsubishi Electric Corporation MELSEC iQ-L Series L04/08/16/32HCPU Firmware versions "05" and prior and Mitsubishi Electric Corporation MELIPC Series MI5122-VW Firmware versions "07" and prior allows a remote unauthenticated attacker to cause a Denial of Service condition in Ethernet communication on the module by sending specially crafted packets. A system reset of the module is required for recovery.

Do I need to act?

~
1.5% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10 High
NETWORK / LOW complexity

Affected Products (19)

Melsec Iq-R R00 Cpu Firmware
Melsec Iq-R R01 Cpu Firmware
Melsec Iq-R R02 Cpu Firmware
Melsec Iq-R R04 Cpu Firmware
Melsec Iq-R R08 Cpu Firmware
Melsec Iq-R R16 Cpu Firmware
Melsec Iq-R R32 Cpu Firmware
Melsec Iq-R R120 Cpu Firmware
Melsec Iq-R R04 Sfcpu Firmware
Melsec Iq-R R08 Sfcpu Firmware
Melsec Iq-R R120 Sfcpu Firmware
Melsec Iq-R R16 Sfcpu Firmware
Melsec Iq-R R32 Sfcpu Firmware
Melsec Iq-R R12 Ccpu-V Firmware
Melipc Mi5122-Vw Firmware
Melsec Iq-L L04 Hcpu Firmware
Melsec Iq-L L08 Hcpu Firmware
Melsec Iq-L L16 Hcpu Firmware
Melsec Iq-L L32 Hcpu Firmware

Affected Vendors

49
/ 100
moderate-risk
Severity 26/34 · High
Exploitability 4/34 · Minimal
Exposure 19/34 · Moderate