Successful exploitation of this remotely exploitable vulnerability, discovered by Faruk Kazi and Parul Sindhwad of COE-CNDS lab, VJTI, Mumbai India, could lead to a communication error and may result in a denial-of-service condition.
The following versions of Mitsubishi Electric India Ethernet communication Extension unit GC-ENET-COM, suffer from the issue: Models with the beginning serial number 16XXXXXXXXX.
CVE-2023-1285 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.5.
The product sees use mainly in the critical manufacturing sector, and on a global basis.
No known public exploits specifically target this vulnerability. However, an attacker could leverage this low complexity vulnerability.
Mitsubishi Electric India released the following countermeasure/mitigation: The firmware of Extension unit GC-ENET-COM where the first 2 digits of the 11-digit serial number starting with “17” have been fixed. The firmware update in Extension unit GC-ENET-COM is only available from the vendor. Users should contact a local Mitsubishi Electric India representative.
In addition, Mitsubishi Electric India recommends users take the following mitigations to minimize the risk of attackers exploiting this vulnerability if the mentioned countermeasures cannot be implemented.
- Use a firewall, virtual private network (VPN), etc. to prevent unauthorized access when Internet access is required
- Locate control system networks and remote devices behind firewalls and isolate them from the business network to restrict access from untrusted networks and hosts
- Restrict physical access to your computer and network equipment on the same network

