« Volver al listado

CVE-2022-25163

Estado: ModificadaCrítica (9.8)—

Improper Input Validation vulnerability in Mitsubishi Electric MELSEC-Q Series QJ71E71-100 first 5 digits of serial number "24061" or prior, Mitsubishi Electric MELSEC-L series LJ71E71-100 first 5 digits of serial number "24061" or prior and Mitsubishi Electric MELSEC iQ-R Series RD81MES96N firmware version "08" or prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on the target products by sending specially crafted packets.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-25163",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Mitsubishi Electric MELSEC-Q Series QJ71E71-100; Mitsubishi Electric MELSEC-L series LJ71E71-100; Mitsubishi Electric MELSEC iQ-R Series RD81MES96N",
          "versions": [
            {
              "status": "affected",
              "version": "Mitsubishi Electric MELSEC-Q Series QJ71E71-100 first 5 digits of serial number \"24061\" or prior"
            },
            {
              "status": "affected",
              "version": "Mitsubishi Electric MELSEC-L series LJ71E71-100 first 5 digits of serial number \"24061\" or prior"
            },
            {
              "status": "affected",
              "version": "Mitsubishi Electric MELSEC iQ-R Series RD81MES96N firmware version \"08\" or prior"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-06-02T18:15:09.527",
  "references": [
    {
      "url": "https://jvn.jp/vu/JVNVU92561747/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp"
    },
    {
      "url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-006_en.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp"
    },
    {
      "url": "https://jvn.jp/vu/JVNVU92561747/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-006_en.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper Input Validation vulnerability in Mitsubishi Electric MELSEC-Q Series QJ71E71-100 first 5 digits of serial number \"24061\" or prior, Mitsubishi Electric MELSEC-L series LJ71E71-100 first 5 digits of serial number \"24061\" or prior and Mitsubishi Electric MELSEC iQ-R Series RD81MES96N firmware version \"08\" or prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on the target products by sending specially crafted packets."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de comprobación de entrada inapropiada en Mitsubishi Electric MELSEC-Q Series QJ71E71-100 primeros 5 dígitos del número de serie \"24061\" o anterior, Mitsubishi Electric MELSEC-L series LJ71E71-100 primeros 5 dígitos del número de serie \"24061\" o anterior y Mitsubishi Electric MELSEC iQ-R Series RD81MES96N versión de firmware \"08\" o anterior permite a un atacante remoto no autenticado causar una condición de denegación de servicio (DoS) o ejecutar código malicioso en los productos de destino mediante el envío de paquetes especialmente diseñados"
    }
  ],
  "lastModified": "2026-06-17T04:33:07.793",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:mitsubishi:melsec_iq-r_rd81mes96n_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EEED33FF-797E-483C-9425-BC2E1C61BA8D",
              "versionEndExcluding": "09"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:mitsubishi:melsec_iq-r_rd81mes96n:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0645C132-7D68-4F30-B307-BE374C05078C"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:mitsubishi:melsec_qj71e71-100_firmware:*:*:*:*:*:*:*:f",
              "vulnerable": true,
              "matchCriteriaId": "AB9663B8-FB95-43B6-8D43-66E2E6D58D34",
              "versionEndExcluding": "24062"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:mistubishi:melsec_qj71e71-100:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AB6F085D-9389-4C55-8648-1319D9B324DD"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:mitsubishi:melsec_lj71e71-100_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CCCFACB4-9F1C-47AA-AD21-75B18F5E37DB",
              "versionEndExcluding": "24062"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:mitsubishi:melsec_lj71e71-100:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4366844C-D226-4C08-9911-BB699216224F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp"
}