CVE-2023-3346
Last modified
CVE-2023-3346 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition and execute arbitrary code on the product by sending specially crafted packets. In addition, system reset is required for recovery.. EPSS estimates a 1.67% chance of exploitation in the next 30 days.
Description
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition and execute arbitrary code on the product by sending specially crafted packets. In addition, system reset is required for recovery.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mitsubishielectric | C80 Firmware | All versions |
| Mitsubishielectric | E70 Firmware | All versions |
| Mitsubishielectric | E80 Firmware | All versions |
| Mitsubishielectric | M70v Firmware | All versions |
| Mitsubishielectric | M720vs Firmware | All versions |
| Mitsubishielectric | M720vs 15-Type Firmware | All versions |
| Mitsubishielectric | M720vw Firmware | All versions |
| Mitsubishielectric | M730vs Firmware | All versions |
| Mitsubishielectric | M730vs 15-Type Firmware | All versions |
| Mitsubishielectric | M730vw Firmware | All versions |
| Mitsubishielectric | M750vs Firmware | All versions |
| Mitsubishielectric | M750vs 15-Type Firmware | All versions |
| Mitsubishielectric | M750vw Firmware | All versions |
| Mitsubishielectric | M80 Firmware | All versions |
| Mitsubishielectric | M800s Firmware | All versions |
| Mitsubishielectric | M800vs Firmware | All versions |
| Mitsubishielectric | M800vw Firmware | All versions |
| Mitsubishielectric | M800w Firmware | All versions |
| Mitsubishielectric | M80v Firmware | All versions |
| Mitsubishielectric | M80vw Firmware | All versions |
| Mitsubishielectric | M80w Firmware | All versions |
References
- https://jvn.jp/vu/JVNVU90352157/index.htmlThird Party Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-208-03Third Party Advisory, US Government Resource
- https://jvn.jp/vu/JVNVU90352157/index.htmlThird Party Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-208-03Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-3346?
How severe is CVE-2023-3346?
How do I fix CVE-2023-3346?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-33439Sourcecodester Faculty Evaluation System v1.0 is vulnerable …7.2
- CVE-2023-3344The Auto Location for WP Job Manager via Google WordPress pl…4.8
- CVE-2023-33440Sourcecodester Faculty Evaluation System v1.0 is vulnerable …7.2
- CVE-2023-33443Incorrect access control in the administrative functionaliti…9.8
- CVE-2023-3345The LMS by Masteriyo WordPress plugin before 1.6.8 does not …6.5
- CVE-2023-33457In Sogou Workflow v0.10.6, memcpy a negtive size in URIParse…8.8
- CVE-2023-33460There's a memory leak in yajl 2.1.0 with use of yajl_tree_pa…6.5
- CVE-2023-33461iniparser v4.1 is vulnerable to NULL Pointer Dereference in …5.5
- CVE-2023-33466Orthanc before 1.12.0 allows authenticated users with access…8.8
- CVE-2023-33468KramerAV VIA Connect (2) and VIA Go (2) devices with a versi…9.1
- CVE-2023-33469In instances where the screen is visible and remote mouse co…7.8
- CVE-2023-3347A vulnerability was found in Samba's SMB2 packet signing mec…5.9
Are you affected by CVE-2023-3346?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
