CVE-2022-25163

CRITICAL

Mitsubishi Melsec Iq-r Rd81mes96n Firmware - Improper Input Validation

Title source: rule
STIX 2.1

Description

Improper Input Validation vulnerability in Mitsubishi Electric MELSEC-Q Series QJ71E71-100 first 5 digits of serial number "24061" or prior, Mitsubishi Electric MELSEC-L series LJ71E71-100 first 5 digits of serial number "24061" or prior and Mitsubishi Electric MELSEC iQ-R Series RD81MES96N firmware version "08" or prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on the target products by sending specially crafted packets.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://jvn.jp/vu/JVNVU92561747/index.html

Scores

CVSS v3 9.8
EPSS 0.0206
EPSS Percentile 78.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (3)
mitsubishi/melsec_iq-r_rd81mes96n_firmware < 09
mitsubishi/melsec_lj71e71-100_firmware < 24062
mitsubishi/melsec_qj71e71-100_firmware < 24062
Published Jun 02, 2022
Tracked Since Feb 18, 2026