CVE-2024-0803 - CVE House
Back to Database
Status published Critical CVE-2024-0803

Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q...

Vulnerability Description

Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on a target product by sending a specially crafted packet.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-0803

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Mitsubishi Electric Corporation

View all reports →

Affected Software

MELSEC-Q Series Q03UDECPU, MELSEC-Q Series Q04UDEHCPU, MELSEC-Q Series Q06UDEHCPU, MELSEC-Q Series Q10UDEHCPU, MELSEC-Q Series Q13UDEHCPU, MELSEC-Q Series Q20UDEHCPU, MELSEC-Q Series Q26UDEHCPU, MELSEC-Q Series Q50UDEHCPU, MELSEC-Q Series Q100UDEHCPU, MELSEC-Q Series Q03UDVCPU, MELSEC-Q Series Q04UDVCPU, MELSEC-Q Series Q06UDVCPU, MELSEC-Q Series Q13UDVCPU, MELSEC-Q Series Q26UDVCPU, MELSEC-Q Series Q04UDPVCPU, MELSEC-Q Series Q06UDPVCPU, MELSEC-Q Series Q13UDPVCPU, MELSEC-Q Series Q26UDPVCPU, MELSEC-L Series L02CPU, MELSEC-L Series L06CPU, MELSEC-L Series L26CPU, MELSEC-L Series L02CPU-P, MELSEC-L Series L06CPU-P, MELSEC-L Series L26CPU-P, MELSEC-L Series L26CPU-BT, MELSEC-L Series L26CPU-PBT
Vulnerable Versions:
The first 5 digits of serial No. "26061" and prior, The first 5 digits of serial No. "26041" and prior

Timeline

Official Publish: March 14th, 2024
Last Modified: August 27th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)