CVE-2022-33324 - CVE House
Back to Database
Status published High CVE-2022-33324

Denial-of-Service Vulnerability in Ethernet port of MELSEC iQ-R, iQ-L Series and MELIPC Series

Vulnerability Description

Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series R00/01/02CPU Firmware versions "32" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120(EN)CPU Firmware versions "65" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R08/16/32/120SFCPU Firmware versions "29" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R08/16/32/120PSFCPU Firmware versions "08" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R12CCPU-V Firmware versions "17" and prior, Mitsubishi Electric Corporation MELSEC iQ-L Series L04/08/16/32HCPU Firmware versions "05" and prior and Mitsubishi Electric Corporation MELIPC Series MI5122-VW Firmware versions "07" and prior allows a remote unauthenticated attacker to cause a Denial of Service condition in Ethernet communication on the module by sending specially crafted packets. A system reset of the module is required for recovery.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-33324

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Mitsubishi Electric Corporation

View all reports →

Affected Software

MELSEC iQ-R Series R00CPU, MELSEC iQ-R Series R01CPU, MELSEC iQ-R Series R02CPU, MELSEC iQ-R Series R04CPU, MELSEC iQ-R Series R08CPU, MELSEC iQ-R Series R16CPU, MELSEC iQ-R Series R32CPU, MELSEC iQ-R Series R120CPU, MELSEC iQ-R Series R04ENCPU, MELSEC iQ-R Series R08ENCPU, MELSEC iQ-R Series R16ENCPU, MELSEC iQ-R Series R32ENCPU, MELSEC iQ-R Series R120ENCPU, MELSEC iQ-R Series R08SFCPU, MELSEC iQ-R Series R16SFCPU, MELSEC iQ-R Series R32SFCPU, MELSEC iQ-R Series R120SFCPU, MELSEC iQ-R Series R12CCPU-V, MELSEC iQ-L Series L04HCPU, MELSEC iQ-L Series L08HCPU, MELSEC iQ-L Series L16HCPU, MELSEC iQ-L Series L32HCPU, MELIPC Series MI5122-VW, MELSEC iQ-R Series R08PSFCPU, MELSEC iQ-R Series R16PSFCPU, MELSEC iQ-R Series R32PSFCPU, MELSEC iQ-R Series R120PSFCPU
Vulnerable Versions:
Firmware versions "32" and prior, Firmware versions "65" and prior, Firmware versions "29" and prior, Firmware versions "17" and prior, Firmware versions "05" and prior, Firmware versions "07" and prior, Firmware versions "08" and prior

Timeline

Official Publish: December 23rd, 2022
Last Modified: September 5th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)