Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-3346— Denial of Service (DoS) and Remote Code Execution Vulnerability in MITSUBISHI CNC Series

CVSS 9.8 · Critical EPSS 1.38% · P80
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-3346

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Denial of Service (DoS) and Remote Code Execution Vulnerability in MITSUBISHI CNC Series
Source: NVD (National Vulnerability Database)
Vulnerability Description
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition and execute arbitrary code on the product by sending specially crafted packets. In addition, system reset is required for recovery.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Mitsubishi Electric CNC Series 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mitsubishi Electric CNC Series是日本三菱电机(Mitsubishi Electric)公司的一系列数控控制系统。 Mitsubishi Electric CNC Series存在安全漏洞,该漏洞源于缓冲区复制时未检查输入大小。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Mitsubishi Electric CorporationMITSUBISHI CNC M800V Series M800VW System Number BND-2051W000 versions A8 and prior -
Mitsubishi Electric CorporationMITSUBISHI CNC M800V Series M800VS System Number BND-2052W000 versions A8 and prior -
Mitsubishi Electric CorporationMITSUBISHI CNC M80V Series M80V System Number BND-2053W000 versions A8 and prior -
Mitsubishi Electric CorporationMITSUBISHI CNC M80V Series M80VW System Number BND-2054W000 versions A8 and prior -
Mitsubishi Electric CorporationMITSUBISHI CNC M800 Series M800W System Number BND-2005W000 versions FB and prior -
Mitsubishi Electric CorporationMITSUBISHI CNC M800 Series M800S System Number BND-2006W000 versions FB and prior -
Mitsubishi Electric CorporationMITSUBISHI CNC M80 Series M80 System Number BND-2007W000 versions FB and prior -
Mitsubishi Electric CorporationMITSUBISHI CNC M80 Series M80W System Number BND-2008W000 versions FB and prior -
Mitsubishi Electric CorporationMITSUBISHI CNC E80 Series E80 System Number BND-2009W000 versions FB and prior -
Mitsubishi Electric CorporationMITSUBISHI CNC C80 Series C80 System Number BND-2036W000 versions BF and prior -
Mitsubishi Electric CorporationMITSUBISHI CNC M700V Series M720VW System Number BND-1015W000 versions LF and prior -
Mitsubishi Electric CorporationMITSUBISHI CNC M700V Series M730VW System Number BND-1015W000 versions LF and prior -
Mitsubishi Electric CorporationMITSUBISHI CNC M700V Series M750VW System Number BND-1015W002 versions LF and prior -
Mitsubishi Electric CorporationMITSUBISHI CNC M700V Series M720VS System Number BND-1012W000 versions LF and prior -
Mitsubishi Electric CorporationMITSUBISHI CNC M700V Series M730VS System Number BND-1012W000 versions LF and prior -
Mitsubishi Electric CorporationMITSUBISHI CNC M700V Series M750VS System Number BND-1012W002 versions LF and prior -
Mitsubishi Electric CorporationMITSUBISHI CNC M70V Series M70V System Number BND-1018W000 versions LF and prior -
Mitsubishi Electric CorporationMITSUBISHI CNC E70 Series E70 System Number BND-1022W000 versions LF and prior -
Mitsubishi Electric CorporationMITSUBISHI CNC IoT Unit Remote Service Gateway Unit System Number BND-2041W001 versions AD and prior -
Mitsubishi Electric CorporationMITSUBISHI CNC IoT Unit Data Acquisition Unit System Number BND-2041W002 all versions -

II. Public POCs for CVE-2023-3346

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-3346

登录查看更多情报信息。

Same Patch Batch · Mitsubishi Electric Corporation · 2023-08-03 · 3 CVEs total

CVE-2023-05257.5 HIGHMitsubishi Electric GOT2000 加密问题漏洞
CVE-2023-33735.9 MEDIUMMitsubishi Electric GOT2000 安全特征问题漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2023-3346

No comments yet


Leave a comment