CVE-2024-1915CWE-468

Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated…

Critical · published March 15, 2024

CVSS v3.1
9.8
EPSS
1%
Percentile
61.9
In the wild
Unconfirmed
What it is

🚨 A remote attacker can craft a packet to unleash malicious code on Mitsubishi MELSEC-Q and MELSEC-L Series CPU modules! 🔥 Think of a factory where the machinery runs on precise commands, like a symphony orchestra following a conductor's baton. If someone sends the wrong signals without authorization, they could throw the entire performance into chaos! An attacker could gain almost unfettered access, executing arbitrary code remotely, which could lead to devastating operational failures or unauthorized control over critical systems. It's like someone infiltrating the control room and pulling all the levers without anyone noticing!

Put simply

Think of a factory where the machinery runs on precise commands, like a symphony orchestra following a conductor's baton. If someone sends the wrong signals without authorization, they could throw the entire performance into chaos! This vulnerability stems from incorrect pointer scaling in the CPU modules, allowing unauthenticated attackers to send specially crafted packets that execute malicious commands, bypassing normal safeguards.

What to do

An attacker could gain almost unfettered access, executing arbitrary code remotely, which could lead to devastating operational failures or unauthorized control over critical systems. It's like someone infiltrating the control room and pulling all the levers without anyone noticing! Immediately update your MELSEC-Q and MELSEC-L Series CPU modules to the latest firmware version provided by Mitsubishi. Additionally, monitor network traffic for any irregularities and consider implementing stricter access controls. 🛡️ You've got this! Follow these steps to secure your systems and keep the factory running smoothly! 💪😊

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.01044 · 61.9th percentile
Weakness
CWE-468 · Incorrect Pointer Scaling
Published
2024-03-15T00:00Z
EPSS history
Timeline
  • 15 MAR 00:00Z
    Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated…
    cvelistv5