三维MELSECi-RQLSeries和MELIPCSeries不当资源锁定

高位可租OT安全插件ID 500662

简表

远程OT资产受脆弱性影响

描述性

Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC-Q Series Q03UDECPU all versions, Mitsubishi Electric MELSEC-Q Series Q04/06/10/13/20/26/50/100UDEHCPU all versions, Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU the first 5 digits of serial number 24051 and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/13/26UDPVCPU the first 5 digits of serial number 24051 and prior, Mitsubishi Electric MELSEC-L series L02/06/26CPU(-P) the first 5 digits of serial number 24051 and prior and Mitsubishi Electric MELSEC-L series L26CPU-(P)BT the first 5 digits of serial number 24051 and prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition in Ethernet communications by sending specially crafted packets.系统重置恢复

插件只对Tenable.ot工作
网站s/www.yyueer.com/products/tenable-ot获取更多信息

求解

下文原由网络安全基础设施安全局创建原创可见于CISA.gov

三菱固定了下列产品的易损性:

MELSECCPU模型
iQ-R串行
R12CCPU-V:固件版本17或以后
查询Aere
Q03UDECPU,Q04/06/10/23/20/50/100UDEHPU:前5位数串数24062或后
Q03/04/06/13/26UDVCPU:24052或后
Q04/06/13/26UPU版本序号前5位数24052或后
L-Serre
L02/06/26CPU-PL26CPU-PBT版本24052或后

MELIPC串行
MI5122-VW:企业版06或以后

三联电报称,近期内会为更多硬件版本提供更多修复三菱减轻这种脆弱风险建议与ISA建议相匹配

更多信息见三菱电工安全咨询

联系三菱电客支持获取更多资料了解如何更新专用硬件

并见

http://www.nessus.org/u?53bebf4a

https://jvn.jp/vu/JVNVU90895626/index.html

https://www.cisa.gov/news-events/ics-advisories/icsa-22-172-01

插件细节

严重性 :高位

身份证 :500662

版本化 :1.3

类型 :远程

家庭问题 :可调用.ot

发布 :7/5/2022

更新 :7/24/2023

风险信息

VPR

风险因子 :低频

分数 :3.6

CVSS v2

风险因子 :高位

基础评分 :7.8

向量 :CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS评分源 :CVE2022249

CVSSv3

风险因子 :高位

基础评分 :7.5

向量 :CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

漏洞信息

CPE系统 :cpe:/o:mitsubishielectric:l02cpu-p_firmware:-,cpe:/o:mitsubishielectric:l02cpu_firmware:-,cpe:/o:mitsubishielectric:l02scpu-p_firmware:-,cpe:/o:mitsubishielectric:l02scpu_firmware:-,cpe:/o:mitsubishielectric:l06cpu-p_firmware:-,cpe:/o:mitsubishielectric:l06cpu_firmware:-,cpe:/o:mitsubishielectric:l26cpu-%28p%29bt_firmware:-,cpe:/o:mitsubishielectric:l26cpu-bt-cm_firmware:-,cpe:/o:mitsubishielectric:l26cpu-bt_firmware:-,cpe:/o:mitsubishielectric:l26cpu-p_firmware:-,cpe:/o:mitsubishielectric:l26cpu-pbt_firmware:-,cpe:/o:mitsubishielectric:l26cpu_firmware:-,cpe:/o:mitsubishielectric:q03udecpu_firmware:-,cpe:/o:mitsubishielectric:q04udehcpu_firmware:-,cpe:/o:mitsubishielectric:q04udpvcpu_firmware:-,cpe:/o:mitsubishielectric:q04udvcpu_firmware:-,cpe:/o:mitsubishielectric:q06ccpu-v_firmware:-,cpe:/o:mitsubishielectric:q06phcpu_firmware:-,cpe:/o:mitsubishielectric:q06udehcpu_firmware:-,cpe:/o:mitsubishielectric:q06udpvcpu_firmware:-,cpe:/o:mitsubishielectric:q06udvcpu_firmware:-,cpe:/o:mitsubishielectric:q100udehcpu_firmware:-,cpe:/o:mitsubishielectric:q10udehcpu_firmware:-,cpe:/o:mitsubishielectric:q13udehcpu_firmware:-,cpe:/o:mitsubishielectric:q13udpvcpu_firmware:-,cpe:/o:mitsubishielectric:q13udvcpu_firmware:-,cpe:/o:mitsubishielectric:q20udehcpu_firmware:-,cpe:/o:mitsubishielectric:q26dhccpu-ls_firmware:-,cpe:/o:mitsubishielectric:q26udehcpu_firmware:-,cpe:/o:mitsubishielectric:q26udpvcpu_firmware:-,cpe:/o:mitsubishielectric:q26udvcpu_firmware:-,cpe:/o:mitsubishielectric:q50udehcpu_firmware:-

需要kb项 :Tenable.ot/Mitsubishi

开发易斯 :无已知利用

补丁发布日期 :6/15/2022

漏洞发布日期 :6/15/2022

参考信息

CVE系统 :CVE2022249

CWE系统 :667

Baidu
map