Back to Database
Status published
Critical
CVE-2024-0803
Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q...
Vulnerability Description
Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on a target product by sending a specially crafted packet.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-0803
Credits & Attribution
No credits recorded in the NVD database.
References
More from Mitsubishi Electric Corporation
View All →CVE-2025-8531
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric...
Medium
6.8
CVE-2025-7731
Information Disclosure Vulnerability in MELSEC iQ-F Series CPU module
High
7.5
CVE-2025-7405
Information Disclosure, Information Tampering, and Denial of Service (DoS) Vulnerability in MELSEC iQ-F Series CPU module
High
7.3
CVE-2025-7376
Information Tampering Vulnerability in Multiple Processes of GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, IoTWorX, MC Works64, and GENESIS
Medium
5.9
CVE-2025-5514
Denial-of-Service(DoS) Vulnerability in Web server function on MELSEC iQ-F Series CPU module
Medium
5.3
Affected Vendor
Mitsubishi Electric Corporation
View all reports →Affected Software
MELSEC-Q Series Q03UDECPU, MELSEC-Q Series Q04UDEHCPU, MELSEC-Q Series Q06UDEHCPU, MELSEC-Q Series Q10UDEHCPU, MELSEC-Q Series Q13UDEHCPU, MELSEC-Q Series Q20UDEHCPU, MELSEC-Q Series Q26UDEHCPU, MELSEC-Q Series Q50UDEHCPU, MELSEC-Q Series Q100UDEHCPU, MELSEC-Q Series Q03UDVCPU, MELSEC-Q Series Q04UDVCPU, MELSEC-Q Series Q06UDVCPU, MELSEC-Q Series Q13UDVCPU, MELSEC-Q Series Q26UDVCPU, MELSEC-Q Series Q04UDPVCPU, MELSEC-Q Series Q06UDPVCPU, MELSEC-Q Series Q13UDPVCPU, MELSEC-Q Series Q26UDPVCPU, MELSEC-L Series L02CPU, MELSEC-L Series L06CPU, MELSEC-L Series L26CPU, MELSEC-L Series L02CPU-P, MELSEC-L Series L06CPU-P, MELSEC-L Series L26CPU-P, MELSEC-L Series L26CPU-BT, MELSEC-L Series L26CPU-PBT
Vulnerable Versions:
The first 5 digits of serial No. "26061" and prior, The first 5 digits of serial No. "26041" and prior
Timeline
Official Publish:
March 14th, 2024
Last Modified:
August 27th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H