CVE-2023-1424

HIGHCVSS 8.1/10EPSS 3.44%

Last modified

CVE-2023-1424 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules and MELSEC iQ-R Series CPU modules allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on a target product by sending specially crafted packets. A system reset of the product is required for recovery from a denial of service (DoS) condition and malicious code execution.. EPSS estimates a 3.44% chance of exploitation in the next 30 days.

Description

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules and MELSEC iQ-R Series CPU modules allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on a target product by sending specially crafted packets. A system reset of the product is required for recovery from a denial of service (DoS) condition and malicious code execution.

Metrics

CVSS 3.1
8.1/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
3.44%

87.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
MitsubishielectricMelsec Iq-Fx5u-32mr\/Ds FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-32mr\/Dss FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-32mr\/Es FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-32mr\/Ess FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-32mt\/Ds FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-32mt\/Dss FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-32mt\/Es FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-32mt\/Ess FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-64mr\/Ds FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-64mr\/Dss FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-64mr\/Es FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-64mr\/Ess FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-64mt\/Ds FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-64mt\/Dss FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-64mt\/Es FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-64mt\/Ess FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-80mr\/Ds FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-80mr\/Dss FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-80mr\/Es FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-80mr\/Ess FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-80mt\/Ds FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-80mt\/Dss FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-80mt\/Es FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5u-80mt\/Ess FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5uc-32mr\/Dds FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5uc-32mr\/Ds FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5uc-32mr\/Ds-Ts FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5uc-32mt\/Dds FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5uc-32mt\/Ds FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5uc-32mt\/Dss-Ts FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5uc-32mt\/Ds-Ts FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5uc-64mr\/Dds FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5uc-64mr\/Ds FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5uc-64mt\/Dds FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5uc-64mt\/Ds FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5uc-96mr\/Dds FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5uc-96mr\/Ds FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5uc-96mt\/Dds FirmwareAll versions
MitsubishielectricMelsec Iq-Fx5uc-96mt\/Ds FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-1424?
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules and MELSEC iQ-R Series CPU modules allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on a target product by sending specially crafted packets. A system reset of the product is required for recovery from a denial of service (DoS) condition and malicious code execution.
How severe is CVE-2023-1424?
CVE-2023-1424 has a CVSS score of 8.1/10 (HIGH severity). The EPSS model estimates a 3.44% probability of exploitation in the next 30 days.
How do I fix CVE-2023-1424?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-1424?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST