7.8
CVE-2022-24946
- EPSS 0.44%
- Veröffentlicht 15.06.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 06:51:26
- Quelle Mitsubishielectric.Psirt@yd.Mi
- CVE-Watchlists
- Unerledigt
Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V firmware versions "16" and prior, Mitsubishi Electric MELSEC-Q Series Q03UDECPU the first 5 digits of serial No. "24061" and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/10/13/20/26/50/100UDEHCPU the first 5 digits of serial No. "24061" and prior, Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/13/26UDPVCPU the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-Q Series Q12DCCPU-V all versions, Mitsubishi Electric MELSEC-Q Series Q24DHCCPU-V(G) all versions, Mitsubishi Electric MELSEC-Q Series Q24/26DHCCPU-LS all versions, Mitsubishi Electric MELSEC-L series L02/06/26CPU(-P) the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-L series L26CPU-(P)BT the first 5 digits of serial number "24051" and prior and Mitsubishi Electric MELIPC Series MI5122-VW firmware versions "05" and prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition in Ethernet communications by sending specially crafted packets. A system reset of the products is required for recovery.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mitsubishielectric ≫ Q03udecpu Firmware Version-
Mitsubishielectric ≫ Q04udehcpu Firmware Version-
Mitsubishielectric ≫ Q04udpvcpu Firmware Version-
Mitsubishielectric ≫ Q04udvcpu Firmware Version-
Mitsubishielectric ≫ Q100udehcpu Firmware Version-
Mitsubishielectric ≫ Q50udehcpu Firmware Version-
Mitsubishielectric ≫ Q26dhccpu-ls Firmware Version-
Mitsubishielectric ≫ Q26udehcpu Firmware Version-
Mitsubishielectric ≫ Q26udpvcpu Firmware Version-
Mitsubishielectric ≫ Q26udvcpu Firmware Version-
Mitsubishielectric ≫ Q20udehcpu Firmware Version-
Mitsubishielectric ≫ Q13udehcpu Firmware Version-
Mitsubishielectric ≫ Q13udpvcpu Firmware Version-
Mitsubishielectric ≫ Q13udvcpu Firmware Version-
Mitsubishielectric ≫ Q10udehcpu Firmware Version-
Mitsubishielectric ≫ Q06ccpu-v Firmware Version-
Mitsubishielectric ≫ Q06phcpu Firmware Version-
Mitsubishielectric ≫ Q06udehcpu Firmware Version-
Mitsubishielectric ≫ Q06udpvcpu Firmware Version-
Mitsubishielectric ≫ Q06udvcpu Firmware Version-
Mitsubishielectric ≫ L02cpu Firmware Version-
Mitsubishielectric ≫ L02cpu-p Firmware Version-
Mitsubishielectric ≫ L02scpu Firmware Version-
Mitsubishielectric ≫ L02scpu-p Firmware Version-
Mitsubishielectric ≫ L06cpu Firmware Version-
Mitsubishielectric ≫ L06cpu-p Firmware Version-
Mitsubishielectric ≫ L26cpu Firmware Version-
Mitsubishielectric ≫ L26cpu-(p)bt Firmware Version-
Mitsubishielectric ≫ L26cpu-bt Firmware Version-
Mitsubishielectric ≫ L26cpu-bt-cm Firmware Version-
Mitsubishielectric ≫ L26cpu-p Firmware Version-
Mitsubishielectric ≫ L26cpu-pbt Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.44% | 0.626 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| nvd@nist.gov | 7.8 | 10 | 6.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:C
|
CWE-667 Improper Locking
The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.