Uncontrolled resource consumption in Mitsubishi Electric MELSEC iQ-R series C Controller Module R12CCPU-V Firmware Versions "16" and prior allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by sending a large number of packets in a short time while the module starting up. System reset is required for recovery.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HMitsubishielectric R12ccpu V
HWMitsubishielectricall versionsMitsubishielectric R12ccpu V Firmware
OSMitsubishielectric≤ 16
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
Related vulnerabilities
CVE-2020-16226CRITICAL9.8PL ✓same product
Podatność na podszywanie się pod urządzenie w produktach Mitsubishi Electric — RCE
CVE-2020-5531CRITICAL9.8PL ✓same product
Zdalne DoS i wykonanie złośliwego kodu w sterownikach Mitsubishi Electric MELSEC/MELIPC
CVE-2023-6943CRITICAL9.8PL ✓same vendor
Unsafe Reflection w oprogramowaniu Mitsubishi Electric — zdalne wykonanie kodu
CVE-2023-4699CRITICAL10.0PL ✓same vendor
Brak uwierzytelnienia w sterownikach PLC i CNC Mitsubishi Electric — RCE
CVE-2023-4562CRITICAL9.1PL ✓same vendor
Pominięcie uwierzytelnienia w sterownikach PLC Mitsubishi MELSEC-F Series