CVE-2023-1424 - CVE House
Back to Database
Status published Critical CVE-2023-1424

Denial-of-Service and Remote Code Execution Vulnerability in MELSEC Series CPU module

Vulnerability Description

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules and MELSEC iQ-R Series CPU modules allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on a target product by sending specially crafted packets. A system reset of the product is required for recovery from a denial of service (DoS) condition and malicious code execution.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-1424

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Mitsubishi Electric Corporation

View all reports →

Affected Software

MELSEC iQ-F Series FX5U-32MT/ES, MELSEC iQ-F Series FX5U-64MT/ES, MELSEC iQ-F Series FX5U-80MT/ES, MELSEC iQ-F Series FX5U-32MR/ES, MELSEC iQ-F Series FX5U-64MR/ES, MELSEC iQ-F Series FX5U-80MR/ES, MELSEC iQ-F Series FX5U-32MT/DS, MELSEC iQ-F Series FX5U-64MT/DS, MELSEC iQ-F Series FX5U-80MT/DS, MELSEC iQ-F Series FX5U-32MR/DS, MELSEC iQ-F Series FX5U-64MR/DS, MELSEC iQ-F Series FX5U-80MR/DS, MELSEC iQ-F Series FX5U-32MT/ESS, MELSEC iQ-F Series FX5U-64MT/ESS, MELSEC iQ-F Series FX5U-80MT/ESS, MELSEC iQ-F Series FX5U-32MT/DSS, MELSEC iQ-F Series FX5U-64MT/DSS, MELSEC iQ-F Series FX5U-80MT/DSS, MELSEC iQ-F Series FX5UC-32MT/D, MELSEC iQ-F Series FX5UC-64MT/D, MELSEC iQ-F Series FX5UC-96MT/D, MELSEC iQ-F Series FX5UC-32MT/DSS, MELSEC iQ-F Series FX5UC-64MT/DSS, MELSEC iQ-F Series FX5UC-96MT/DSS, MELSEC iQ-F Series FX5UC-32MT/DS-TS, MELSEC iQ-F Series FX5UC-32MT/DSS-TS, MELSEC iQ-F Series FX5UC-32MR/DS-TS, MELSEC iQ-R Series R00CPU, MELSEC iQ-R Series R01CPU, MELSEC iQ-R Series R02CPU, MELSEC iQ-R Series R04CPU, MELSEC iQ-R Series R08CPU, MELSEC iQ-R Series R16CPU, MELSEC iQ-R Series R32CPU, MELSEC iQ-R Series R120CPU, MELSEC iQ-R Series R04ENCPU, MELSEC iQ-R Series R08ENCPU, MELSEC iQ-R Series R16ENCPU, MELSEC iQ-R Series R32ENCPU, MELSEC iQ-R Series R120ENCPU, MELSEC iQ-R Series R08SFCPU, MELSEC iQ-R Series R16SFCPU, MELSEC iQ-R Series R32SFCPU, MELSEC iQ-R Series R120SFCPU, MELSEC iQ-R Series R08PCPU, MELSEC iQ-R Series R16PCPU, MELSEC iQ-R Series R32PCPU, MELSEC iQ-R Series R120PCPU
Vulnerable Versions:
Serial number 17X**** or later, versions from 1.220 to 1.281, versions from 1.220 to 1.281, versions 35 and prior, versions from 12 to 68, versions from 26 to 31, versions from 3 to 37

Timeline

Official Publish: May 24th, 2023
Last Modified: March 5th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)