7.5

CVE-2022-33323

Authentication Bypass Vulnerability in Robot Controller of MELFA SD/SQ series and F-series

Active Debug Code vulnerability in robot controller of Mitsubishi Electric Corporation industrial robot MELFA SD/SQ Series and MELFA F-Series allows a remote unauthenticated attacker to gain unauthorized access by authentication bypass through an unauthorized telnet login. As for the affected model names, controller types and firmware versions, see the Mitsubishi Electric's advisory which is listed in [References] section.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MitsubishielectricRv-2f Firmware Version-
   MitsubishielectricRv-2f Version-
MitsubishielectricRv-4f Firmware Version-
   MitsubishielectricRv-4f Version-
MitsubishielectricRv-7f Firmware Version-
   MitsubishielectricRv-7f Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.14% 0.625
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE-489 Active Debug Code

The product is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information.

https://jvn.jp/vu/JVNVU94588481/index.html
Third Party Advisory
https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-05
Third Party Advisory
US Government Resource
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-020_en.pdf
Vendor Advisory