Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-1424— Denial-of-Service and Remote Code Execution Vulnerability in MELSEC Series CPU module

CVSS 10.0 · Critical EPSS 3.67% · P88
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-1424

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Denial-of-Service and Remote Code Execution Vulnerability in MELSEC Series CPU module
Source: NVD (National Vulnerability Database)
Vulnerability Description
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules and MELSEC iQ-R Series CPU modules allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on a target product by sending specially crafted packets. A system reset of the product is required for recovery from a denial of service (DoS) condition and malicious code execution.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Mitsubishi Electric MELSEC iQ-F Series 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mitsubishi Electric MELSEC iQ-F series是日本三菱电机(Mitsubishi Electric)公司的一款可编程逻辑控制器。 Mitsubishi Electric MELSEC iQ-F Series存在安全漏洞,该漏洞源于CPU模块中向缓冲区写入超过缓冲区能保存的最大数据量的数据,从而导致系统拒绝服务。攻击者利用该漏洞可以执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5U-32MT/ES Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5U-64MT/ES Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5U-80MT/ES Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5U-32MR/ES Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5U-64MR/ES Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5U-80MR/ES Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5U-32MT/DS Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5U-64MT/DS Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5U-80MT/DS Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5U-32MR/DS Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5U-64MR/DS Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5U-80MR/DS Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5U-32MT/ESS Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5U-64MT/ESS Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5U-80MT/ESS Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5U-32MT/DSS Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5U-64MT/DSS Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5U-80MT/DSS Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5UC-32MT/D Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5UC-64MT/D Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5UC-96MT/D Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5UC-32MT/DSS Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5UC-64MT/DSS Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5UC-96MT/DSS Serial number 17X**** or later, versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5UC-32MT/DS-TS versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5UC-32MT/DSS-TS versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-F Series FX5UC-32MR/DS-TS versions from 1.220 to 1.281 -
Mitsubishi Electric CorporationMELSEC iQ-R Series R00CPU versions 35 and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R01CPU versions 35 and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R02CPU versions 35 and prior -
Mitsubishi Electric CorporationMELSEC iQ-R Series R04CPU versions from 12 to 68 -
Mitsubishi Electric CorporationMELSEC iQ-R Series R08CPU versions from 12 to 68 -
Mitsubishi Electric CorporationMELSEC iQ-R Series R16CPU versions from 12 to 68 -
Mitsubishi Electric CorporationMELSEC iQ-R Series R32CPU versions from 12 to 68 -
Mitsubishi Electric CorporationMELSEC iQ-R Series R120CPU versions from 12 to 68 -
Mitsubishi Electric CorporationMELSEC iQ-R Series R04ENCPU versions from 12 to 68 -
Mitsubishi Electric CorporationMELSEC iQ-R Series R08ENCPU versions from 12 to 68 -
Mitsubishi Electric CorporationMELSEC iQ-R Series R16ENCPU versions from 12 to 68 -
Mitsubishi Electric CorporationMELSEC iQ-R Series R32ENCPU versions from 12 to 68 -
Mitsubishi Electric CorporationMELSEC iQ-R Series R120ENCPU versions from 12 to 68 -
Mitsubishi Electric CorporationMELSEC iQ-R Series R08SFCPU versions from 26 to 31 -
Mitsubishi Electric CorporationMELSEC iQ-R Series R16SFCPU versions from 26 to 31 -
Mitsubishi Electric CorporationMELSEC iQ-R Series R32SFCPU versions from 26 to 31 -
Mitsubishi Electric CorporationMELSEC iQ-R Series R120SFCPU versions from 26 to 31 -
Mitsubishi Electric CorporationMELSEC iQ-R Series R08PCPU versions from 3 to 37 -
Mitsubishi Electric CorporationMELSEC iQ-R Series R16PCPU versions from 3 to 37 -
Mitsubishi Electric CorporationMELSEC iQ-R Series R32PCPU versions from 3 to 37 -
Mitsubishi Electric CorporationMELSEC iQ-R Series R120PCPU versions from 3 to 37 -

II. Public POCs for CVE-2023-1424

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-1424

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2023-1424

No comments yet


Leave a comment