Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-33324— Denial-of-Service Vulnerability in Ethernet port of MELSEC iQ-R, iQ-L Series and MELIPC Series

CVSS 7.5 · High EPSS 1.56% · P82
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-33324

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Denial-of-Service Vulnerability in Ethernet port of MELSEC iQ-R, iQ-L Series and MELIPC Series
Source: NVD (National Vulnerability Database)
Vulnerability Description
Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series R00/01/02CPU Firmware versions "32" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120(EN)CPU Firmware versions "65" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R08/16/32/120SFCPU Firmware versions "29" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R08/16/32/120PSFCPU Firmware versions "08" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R12CCPU-V Firmware versions "17" and prior, Mitsubishi Electric Corporation MELSEC iQ-L Series L04/08/16/32HCPU Firmware versions "05" and prior and Mitsubishi Electric Corporation MELIPC Series MI5122-VW Firmware versions "07" and prior allows a remote unauthenticated attacker to cause a Denial of Service condition in Ethernet communication on the module by sending specially crafted packets. A system reset of the module is required for recovery.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
不恰当的资源关闭或释放
Source: NVD (National Vulnerability Database)
Vulnerability Title
Mitsubishi Electric MELSEC iQ-R、iQ-L Series 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mitsubishi Electric MELSEC iQ-R series和Mitsubishi Electric MELSEC iQ-L Series都是日本三菱电机(Mitsubishi Electric)公司的产品。Mitsubishi Electric MELSEC iQ-R series是一款可编程逻辑控制器。Mitsubishi Electric MELSEC iQ-L Series是一系列可编程逻辑控制器。 Mitsubishi Electric MELSEC iQ-R、iQ-L Seri
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Mitsubishi Electric CorporationMELSEC iQ-R Series R00CPU Firmware versions "32" and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R01CPU Firmware versions "32" and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R02CPU Firmware versions "32" and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R04CPU Firmware versions "65" and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R08CPU Firmware versions "65" and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R16CPU Firmware versions "65" and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R32CPU Firmware versions "65" and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R120CPU Firmware versions "65" and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R04ENCPU Firmware versions "65" and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R08ENCPU Firmware versions "65" and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R16ENCPU Firmware versions "65" and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R32ENCPU Firmware versions "65" and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R120ENCPU Firmware versions "65" and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R08SFCPU Firmware versions "29" and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R16SFCPU Firmware versions "29" and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R32SFCPU Firmware versions "29" and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R120SFCPU Firmware versions "29" and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R12CCPU-V Firmware versions "17" and prior -
Mitsubishi Electric CorporationMELSEC iQ-L Series L04HCPU Firmware versions "05" and prior -
Mitsubishi Electric CorporationMELSEC iQ-L Series L08HCPU Firmware versions "05" and prior -
Mitsubishi Electric CorporationMELSEC iQ-L Series L16HCPU Firmware versions "05" and prior -
Mitsubishi Electric CorporationMELSEC iQ-L Series L32HCPU Firmware versions "05" and prior -
Mitsubishi Electric CorporationMELIPC Series MI5122-VW Firmware versions "07" and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R08PSFCPU Firmware versions "08" and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R16PSFCPU Firmware versions "08" and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R32PSFCPU Firmware versions "08" and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R120PSFCPU Firmware versions "08" and prior -

II. Public POCs for CVE-2022-33324

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-33324

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2022-33324

No comments yet


Leave a comment