CVE-2024-0802CWE-468

Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated…

Critical · published March 14, 2024

CVSS v3.1
9.8
EPSS
1%
Percentile
62.5
In the wild
Unconfirmed
What it is

🚨 A crafty packet is all it takes to open the door to your Mitsubishi MELSEC systems! Think of it like an intruder who can sneak into a factory through a back door, reading confidential plans or even altering machinery settings without anyone noticing. This vulnerability allows remote attackers to access sensitive information or run malicious code as if they belonged there! An attacker could exploit this vulnerability to read arbitrary data from your CPU modules or execute harmful code, potentially compromising your entire system's integrity. This could lead to unauthorized operations, data breaches, and even operational downtime, which would be absolutely devastating for your organization.

Put simply

Think of it like an intruder who can sneak into a factory through a back door, reading confidential plans or even altering machinery settings without anyone noticing. This vulnerability allows remote attackers to access sensitive information or run malicious code as if they belonged there! This Incorrect Pointer Scaling vulnerability in the MELSEC-Q and MELSEC-L Series CPU modules enables an unauthenticated attacker to send specially crafted network packets that can be interpreted in harmful ways, allowing for unauthorized access and code execution.

What to do

An attacker could exploit this vulnerability to read arbitrary data from your CPU modules or execute harmful code, potentially compromising your entire system's integrity. This could lead to unauthorized operations, data breaches, and even operational downtime, which would be absolutely devastating for your organization. To safeguard your systems, update your CPU modules to the latest firmware version immediately and implement strict network access controls to limit exposure. Regularly audit your network traffic for unusual packet patterns that could indicate exploitation attempts. You've got this! By taking these steps, you'll enhance your security posture and keep your systems safe. 🛡️

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.01066 · 62.5th percentile
Weakness
CWE-468 · Incorrect Pointer Scaling
Published
2024-03-14T23:57Z
EPSS history
Timeline
  • 14 MAR 23:57Z
    Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated…
    cvelistv5