Mitsubishi Electric fixed an improper input validation vulnerability in its MELSEC iQ-R Series, according to a report with CISA.

Successful exploitation of this remotely exploitable vulnerability, which Mitsubishi self-reported, could allow a remote unauthenticated attacker to cause a denial-of-service condition on a target product by sending specially crafted packets.

The following Mitsubishi Electric MELSEC iQ-R Series products suffer from the issue:

  • RJ71EN71: Firmware version “65” and prior
  • R04/08/16/32/120ENCPU: Network part firmware version “65” and prior

In the vulnerability, MELSEC iQ-R Series RJ71EN71 products with firmware versions prior to “65” and R04/08/16/32/120ENCPU products with Network firmware versions prior to “65” are vulnerable to improper input validation. A remote unauthenticated user could cause a denial-of-service condition on a target product by sending specially crafted packets. A system reset is required to recover from a denial-of-service condition.

Schneider Bold

CVE-2022-40265 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 8.6.

The product sees use mainly in the critical manufacturing sector, and on a global basis.

No known public exploits specifically target this vulnerability. However, an attacker with low skill level could leverage this low complexity vulnerability.

Mitsubishi Electric fixed the vulnerability in the following MELSEC iQ-R Series products:

Users should refer to the following product manual for instructions to update firmware: MELSEC iQ-R Module Configuration Manual “Firmware Update Function.” 

Mitsubishi Electric recommends users take the following mitigation measures to minimize the risk of an unauthenticated user exploiting this vulnerability:

  • Use a firewall, virtual private network (VPN), etc. to prevent unauthorized access when Internet access is required
  • Use the product within a local area network (LAN)
  • Block access from untrusted networks and hosts through firewalls
  • Use the IP filter function to restrict the accessible IP addresses

For using the IP filter function, users should see MELSEC iQ-R Ethernet User’s Manual (Application) Security “IP filter.”

Users can refer to the Mitsubishi Electric advisory for further details.

ISSSource

Pin It on Pinterest

Share This