CVE-2022-33323
Last modified
CVE-2022-33323 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Active Debug Code vulnerability in robot controller of Mitsubishi Electric Corporation industrial robot MELFA SD/SQ Series and MELFA F-Series allows a remote unauthenticated attacker to gain unauthorized access by authentication bypass through an unauthorized telnet login. As for the affected model names, controller types and firmware versions, see the Mitsubishi Electric's advisory which is listed in [References] section.. EPSS estimates a 1.14% chance of exploitation in the next 30 days.
Description
Active Debug Code vulnerability in robot controller of Mitsubishi Electric Corporation industrial robot MELFA SD/SQ Series and MELFA F-Series allows a remote unauthenticated attacker to gain unauthorized access by authentication bypass through an unauthorized telnet login. As for the affected model names, controller types and firmware versions, see the Mitsubishi Electric's advisory which is listed in [References] section.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mitsubishielectric | Rh-12sdh55 Firmware | All versions |
| Mitsubishielectric | Rh-12sdh70 Firmware | All versions |
| Mitsubishielectric | Rh-12sdh85 Firmware | All versions |
| Mitsubishielectric | Rh-12sqh55 Firmware | All versions |
| Mitsubishielectric | Rh-12sqh70 Firmware | All versions |
| Mitsubishielectric | Rh-12sqh85 Firmware | All versions |
| Mitsubishielectric | Rh-20sdh100 Firmware | All versions |
| Mitsubishielectric | Rh-20sdh85 Firmware | All versions |
| Mitsubishielectric | Rh-20sqh85 Firmware | All versions |
| Mitsubishielectric | Rh-3sdhr Firmware | All versions |
| Mitsubishielectric | Rh-3sqhr Firmware | All versions |
| Mitsubishielectric | Rh-6sdh35 Firmware | All versions |
| Mitsubishielectric | Rh-6sdh45 Firmware | All versions |
| Mitsubishielectric | Rh-6sdh55 Firmware | All versions |
| Mitsubishielectric | Rh-6sqh35 Firmware | All versions |
| Mitsubishielectric | Rh-6sqh45 Firmware | All versions |
| Mitsubishielectric | Rh-6sqh55 Firmware | All versions |
| Mitsubishielectric | Rv-12sd Firmware | All versions |
| Mitsubishielectric | Rv-12sdl Firmware | All versions |
| Mitsubishielectric | Rv-12sq Firmware | All versions |
| Mitsubishielectric | Rv-12sql Firmware | All versions |
| Mitsubishielectric | Rv-2sdb Firmware | All versions |
| Mitsubishielectric | Rv-2sqb Firmware | All versions |
| Mitsubishielectric | Rv-3sd Firmware | All versions |
| Mitsubishielectric | Rv-3sdj Firmware | All versions |
| Mitsubishielectric | Rv-3sq Firmware | All versions |
| Mitsubishielectric | Rv-3sqj Firmware | All versions |
| Mitsubishielectric | Rv-6sd Firmware | All versions |
| Mitsubishielectric | Rv-6sdl Firmware | All versions |
| Mitsubishielectric | Rv-6sq Firmware | All versions |
| Mitsubishielectric | Rv-6sql Firmware | All versions |
| Mitsubishielectric | Rh-12fh55 Firmware | All versions |
| Mitsubishielectric | Rh-12fh70 Firmware | All versions |
| Mitsubishielectric | Rh-12fh85 Firmware | All versions |
| Mitsubishielectric | Rh-20fh100 Firmware | All versions |
| Mitsubishielectric | Rh-20fh85 Firmware | All versions |
| Mitsubishielectric | Rh-3fh35 Firmware | All versions |
| Mitsubishielectric | Rh-3fh45 Firmware | All versions |
| Mitsubishielectric | Rh-3fh55 Firmware | All versions |
| Mitsubishielectric | Rh-6fh35 Firmware | All versions |
| Mitsubishielectric | Rh-6fh45 Firmware | All versions |
| Mitsubishielectric | Rh-6fh55 Firmware | All versions |
| Mitsubishielectric | Rv-13f Firmware | All versions |
| Mitsubishielectric | Rv-13fl Firmware | All versions |
| Mitsubishielectric | Rv-20f Firmware | All versions |
| Mitsubishielectric | Rv-2f Firmware | All versions |
| Mitsubishielectric | Rv-4f Firmware | All versions |
| Mitsubishielectric | Rv-4fl Firmware | All versions |
| Mitsubishielectric | Rv-7f Firmware | All versions |
| Mitsubishielectric | Rv-7fl Firmware | All versions |
Showing 50 of 51 affected configurations. See NVD for the full list.
References
- https://jvn.jp/vu/JVNVU94588481/index.htmlThird Party Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-05Third Party Advisory, US Government Resource
- https://jvn.jp/vu/JVNVU94588481/index.htmlThird Party Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-05Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-33323?
How severe is CVE-2022-33323?
How do I fix CVE-2022-33323?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-33318Deserialization of Untrusted Data vulnerability in Mitsubish…9.8
- CVE-2022-33319Out-of-bounds Read vulnerability in Mitsubishi Electric GENE…9.1
- CVE-2022-3332A vulnerability classified as critical has been found in Sou…9.8
- CVE-2022-33320Deserialization of Untrusted Data vulnerability in Mitsubish…7.8
- CVE-2022-33321Cleartext Transmission of Sensitive Information vulnerabilit…9.8
- CVE-2022-33322Cross-site scripting vulnerability in Mitsubishi Electric co…6.1
- CVE-2022-33324Improper Resource Shutdown or Release vulnerability in Mitsu…7.5
- CVE-2022-33325Multiple command injection vulnerabilities exist in the web_…9.8
- CVE-2022-33326Multiple command injection vulnerabilities exist in the web_…9.8
- CVE-2022-33327Multiple command injection vulnerabilities exist in the web_…9.8
- CVE-2022-33328Multiple command injection vulnerabilities exist in the web_…9.8
- CVE-2022-33329Multiple command injection vulnerabilities exist in the web_…9.8
Are you affected by CVE-2022-33323?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
