CVE-2022-25161
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
18/05/2022
Last modified:
06/06/2022
Description
Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 17X**** or later and versions prior to 1.270, Mitsubishi Electric Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 179**** and prior and versions prior to 1.073, MELSEC iQ-F series FX5UC-xMy/z(x=32,64,96, y=T,R, z=D,DSS) with serial number 17X**** or later and versions prior to 1.270, Mitsubishi Electric MELSEC iQ-F series FX5UC-xMy/z(x=32,64,96, y=T,R, z=D,DSS) with serial number 179**** and prior and versions prior to 1.073, Mitsubishi Electric MELSEC iQ-F series FX5UC-32MT/DS-TS versions prior to 1.270, Mitsubishi Electric MELSEC iQ-F series FX5UC-32MT/DSS-TS versions prior to 1.270, Mitsubishi Electric MELSEC iQ-F series FX5UC-32MR/DS-TS versions prior to 1.270, Mitsubishi Electric MELSEC iQ-F series FX5UJ-xMy/z(x=24,40,60, y=T,R, z=ES,ESS) versions prior to 1.030, Mitsubishi Electric MELSEC iQ-F series FX5UJ-xMy/ES-A(x=24,40,60, y=T,R) versions prior to 1.031 and Mitsubishi Electric MELSEC iQ-F series FX5S-xMy/z(x=30,40,60,80, y=T,R, z=ES,ESS) version 1.000 allows a remote unauthenticated attacker to cause a DoS condition for the product's program execution or communication by sending specially crafted packets. System reset of the product is required for recovery.
Impact
Base Score 3.x
8.60
Severity 3.x
HIGH
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:mitsubishielectric:melsec_iq-fx5u-32mt\/es_firmware:*:*:*:*:*:*:*:* | 1.270 (excluding) | |
| cpe:2.3:h:mitsubishielectric:melsec_iq-fx5u-32mt\/es:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:melsec_iq-fx5u-32mt\/ds_firmware:*:*:*:*:*:*:*:* | 1.270 (excluding) | |
| cpe:2.3:h:mitsubishielectric:melsec_iq-fx5u-32mt\/ds:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:melsec_iq-fx5u-32mt\/ess_firmware:*:*:*:*:*:*:*:* | 1.270 (excluding) | |
| cpe:2.3:h:mitsubishielectric:melsec_iq-fx5u-32mt\/ess:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:melsec_iq-fx5u-32mt\/dss_firmware:*:*:*:*:*:*:*:* | 1.270 (excluding) | |
| cpe:2.3:h:mitsubishielectric:melsec_iq-fx5u-32mt\/dss:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:melsec_iq-fx5u-32mr\/es_firmware:*:*:*:*:*:*:*:* | 1.270 (excluding) | |
| cpe:2.3:h:mitsubishielectric:melsec_iq-fx5u-32mr\/es:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:melsec_iq-fx5u-32mr\/ds_firmware:*:*:*:*:*:*:*:* | 1.270 (excluding) | |
| cpe:2.3:h:mitsubishielectric:melsec_iq-fx5u-32mr\/ds:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:melsec_iq-fx5u-32mr\/ess_firmware:*:*:*:*:*:*:*:* | 1.270 (excluding) | |
| cpe:2.3:h:mitsubishielectric:melsec_iq-fx5u-32mr\/ess:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:melsec_iq-fx5u-32mr\/dss_firmware:*:*:*:*:*:*:*:* | 1.270 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



