Uncontrolled resource consumption in Mitsubishi Electric MELSEC iQ-R series C Controller Module R12CCPU-V Firmware Versions "16" and prior allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by sending a large number of packets in a short time while the module starting up. System reset is required for recovery.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HMitsubishielectric R12ccpu V
HWMitsubishielectricwszystkie wersjeMitsubishielectric R12ccpu V Firmware
OSMitsubishielectric≤ 16
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Auth Bypass
CWE
Powiązane podatności
CVE-2020-16226CRITICAL9.8PL ✓ten sam produkt
Podatność na podszywanie się pod urządzenie w produktach Mitsubishi Electric — RCE
CVE-2020-5531CRITICAL9.8PL ✓ten sam produkt
Zdalne DoS i wykonanie złośliwego kodu w sterownikach Mitsubishi Electric MELSEC/MELIPC
CVE-2023-6943CRITICAL9.8PL ✓ten sam vendor
Unsafe Reflection w oprogramowaniu Mitsubishi Electric — zdalne wykonanie kodu
CVE-2023-4699CRITICAL10.0PL ✓ten sam vendor
Brak uwierzytelnienia w sterownikach PLC i CNC Mitsubishi Electric — RCE
CVE-2023-4562CRITICAL9.1PL ✓ten sam vendor
Pominięcie uwierzytelnienia w sterownikach PLC Mitsubishi MELSEC-F Series