8.6
CVE-2022-40265
- EPSS 0.28%
- Veröffentlicht 30.11.2022 01:15:09
- Zuletzt bearbeitet 21.11.2024 07:21:09
- Quelle Mitsubishielectric.Psirt@yd.Mi
- CVE-Watchlists
- Unerledigt
Improper Input Validation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series RJ71EN71 Firmware version "65" and prior and Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120ENCPU Network Part Firmware version "65" and prior allows a remote unauthenticated attacker to cause a Denial of Service condition by sending specially crafted packets. A system reset is required for recovery.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mitsubishielectric ≫ Rj71en71 Firmware Version <= 65
Mitsubishielectric ≫ R04encpu Firmware Version <= 65
Mitsubishielectric ≫ R08encpu Firmware Version <= 65
Mitsubishielectric ≫ R16encpu Firmware Version <= 65
Mitsubishielectric ≫ R32encpu Firmware Version <= 65
Mitsubishielectric ≫ R120encpu Firmware Version <= 65
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.51 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp | 8.6 | 3.9 | 4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.