7.5

CVE-2022-33323

Authentication Bypass Vulnerability in Robot Controller of MELFA SD/SQ series and F-series

Active Debug Code vulnerability in robot controller of Mitsubishi Electric Corporation industrial robot MELFA SD/SQ Series and MELFA F-Series allows a remote unauthenticated attacker to gain unauthorized access by authentication bypass through an unauthorized telnet login. As for the affected model names, controller types and firmware versions, see the Mitsubishi Electric's advisory which is listed in [References] section.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mitsubishielectric ≫ Rv-3sd Firmware Version -
   Mitsubishielectric ≫ Rv-3sd Version -
Mitsubishielectric ≫ Rv-3sq Firmware Version -
   Mitsubishielectric ≫ Rv-3sq Version -
Mitsubishielectric ≫ Rv-6sd Firmware Version -
   Mitsubishielectric ≫ Rv-6sd Version -
Mitsubishielectric ≫ Rv-6sq Firmware Version -
   Mitsubishielectric ≫ Rv-6sq Version -
Mitsubishielectric ≫ Rv-13f Firmware Version -
   Mitsubishielectric ≫ Rv-13f Version -
Mitsubishielectric ≫ Rv-20f Firmware Version -
   Mitsubishielectric ≫ Rv-20f Version -
Mitsubishielectric ≫ Rv-2f Firmware Version -
   Mitsubishielectric ≫ Rv-2f Version -
Mitsubishielectric ≫ Rv-4f Firmware Version -
   Mitsubishielectric ≫ Rv-4f Version -
Mitsubishielectric ≫ Rv-4fl Firmware Version -
   Mitsubishielectric ≫ Rv-4fl Version -
Mitsubishielectric ≫ Rv-7f Firmware Version -
   Mitsubishielectric ≫ Rv-7f Version -
Mitsubishielectric ≫ Rv-7fl Firmware Version -
   Mitsubishielectric ≫ Rv-7fl Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.14% 0.625
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE-489 Active Debug Code

The product is released with debugging code still enabled or active.

https://jvn.jp/vu/JVNVU94588481/index.html
Third Party Advisory
https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-05
Third Party Advisory
US Government Resource
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-020_en.pdf
Vendor Advisory