Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p5m3-f8vg-7g3w

Опубликовано: 03 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Improper Input Validation vulnerability in Mitsubishi Electric MELSEC-Q Series QJ71E71-100 first 5 digits of serial number "24061" or prior, Mitsubishi Electric MELSEC-L series LJ71E71-100 first 5 digits of serial number "24061" or prior and Mitsubishi Electric MELSEC iQ-R Series RD81MES96N firmware version "08" or prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on the target products by sending specially crafted packets.

Improper Input Validation vulnerability in Mitsubishi Electric MELSEC-Q Series QJ71E71-100 first 5 digits of serial number "24061" or prior, Mitsubishi Electric MELSEC-L series LJ71E71-100 first 5 digits of serial number "24061" or prior and Mitsubishi Electric MELSEC iQ-R Series RD81MES96N firmware version "08" or prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on the target products by sending specially crafted packets.

EPSS

Процентиль: 72%
0.0073
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

Improper Input Validation vulnerability in Mitsubishi Electric MELSEC-Q Series QJ71E71-100 first 5 digits of serial number "24061" or prior, Mitsubishi Electric MELSEC-L series LJ71E71-100 first 5 digits of serial number "24061" or prior and Mitsubishi Electric MELSEC iQ-R Series RD81MES96N firmware version "08" or prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on the target products by sending specially crafted packets.

CVSS3: 9.8
fstec
больше 3 лет назад

Уязвимость микропрограммного обеспечения программируемых логических контроллеров MELSEC-Q Series QJ71E71-100, MELSEC-L Series LJ71E71-100 и MELSEC iQ-R Series RD81MES96N, существующая из-за недостаточной проверки входных данных, позволяющая нарушителю вызвать отказ в обслуживании или выполнить вредоносный код

EPSS

Процентиль: 72%
0.0073
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20