Mitsubishi Electric iQ-F CPU module
cpe:2.3:h:mitsubishielectric:melsec_iq-f:*:*:*:*:*:*:*, +49 more
A denial-of-service vulnerability has been identified in the TCP communication function of the Mitsubishi Electric MELSEC iQ-F Series CPU module. This vulnerability allows remote attackers to disconnect an active connection by sending specially crafted TCP packets, creating a DoS condition on the affected product. Notably, this issue only impacts the connection under attack, with no effects on other active connections.
Exploitation of this vulnerability leads to a denial-of-service condition, where the targeted TCP connection is abruptly disconnected. To recover from this state, the connection must be manually re-established.
Mitsubishi Electric has no plans to release a fixed version for this vulnerability. Instead, the company recommends using a virtual private network (VPN) to encrypt communications when Internet access is necessary, and restricting physical access to the affected products and their connected LAN.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.