Mitsubishi Electric MELSEC-Q Series PLCs Resource Exhaustion
Published Feb 5, 2019
7.5
HIGHCVSS 3.1
EPSS 4.27%
Description
Mitsubishi Electric Q03/04/06/13/26UDVCPU: serial number 20081 and prior, Q04/06/13/26UDPVCPU: serial number 20081 and prior, and Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU: serial number 20101 and prior. A remote attacker can send specific bytes over Port 5007 that will result in an Ethernet stack crash and disruption to USB communication.
Affected products
-
- Version 0StatusaffectedConstraints<=serial number 20081
- Version
-
- Version 0StatusaffectedConstraints<=serial number 20081
- Version 0StatusaffectedConstraints<=serial number 20101
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Mitsubishi Electric | Q04/06/13/26udpvcpu | unaffected |
| |||||||||
| Mitsubishi Electric | n/a | unaffected |
|
Configuration 1
- ≤ 20081
Running on/with
- n/a
Configuration 2
- ≤ 20081
Running on/with
- n/a
Configuration 3
- ≤ 20081
Running on/with
- n/a
Configuration 4
- ≤ 20081
Running on/with
- n/a
Configuration 5
- ≤ 20081
Running on/with
- n/a
Configuration 6
- ≤ 20081
Running on/with
- n/a
Configuration 7
- ≤ 20081
Running on/with
- n/a
Configuration 8
- ≤ 20081
Running on/with
- n/a
Configuration 9
- ≤ 20081
Running on/with
- n/a
Configuration 10
- ≤ 20101
Running on/with
- n/a
Configuration 11
- ≤ 20101
Running on/with
- n/a
Configuration 12
- ≤ 20101
Running on/with
- n/a
Configuration 13
- ≤ 20101
Running on/with
- n/a
Configuration 14
- ≤ 20101
Running on/with
- n/a
Configuration 15
- ≤ 20101
Running on/with
- n/a
Configuration 16
- ≤ 20101
Running on/with
- n/a
Configuration 17
- ≤ 20101
Running on/with
- n/a
Configuration 18
- ≤ 20101
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Mitsubishi Electric has produced a new version of the firmware. Additional information about this vulnerability or Mitsubishi Electric's compensating control is available by contacting a local Mitsubishi Electric representative, which can be found at the following location: https://us.mitsubishielectric.com/fa/en/about-us/distributors
Mitsubishi Electric strongly recommends users should operate the affected device behind a firewall.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.27% (0.04274) | 90.79th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.27% (0.04274) | 89.78th | v5 (v2026.06.15) |
| Feb 2, 2026 | 1.49% (0.01491) | 80.78th | v4 (v2025.03.14) |
| Jun 27, 2025 | 3.59% (0.03587) | 87.25th | v4 (v2025.03.14) |
| Jul 20, 2024 | 0.13% (0.00133) | 48.86th | v3 (v2023.03.01) |
| Jun 21, 2024 | 0.13% (0.00133) | 48.62th | v3 (v2023.03.01) |
| Dec 12, 2023 | 0.18% (0.00176) | 54.60th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.19% (0.00187) | 54.36th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.05% (0.01055) | 52.13th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.05% (0.01055) | 48.43th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.50% (0.04499) | 74.08th | v2 (v2022.01.01) |
| Feb 3, 2022 | 3.43% (0.03427) | 68.31th | v5 (v2026.06.15) |
| Jan 6, 2022 | 3.43% (0.03427) | 68.01th | v1 |
| Sep 1, 2021 | 0.78% (0.00785) | 52.07th | v1 |
| Apr 14, 2021 | 0.78% (0.00785) | 0.00th | v1 |
References (3)
- http://www.securityfocus.com/bid/106771 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-19-029-02 Third Party AdvisoryUS Government Resource
- https://www.cisa.gov/news-events/ics-advisories/icsa-19-029-02 x_refsource_MISC
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/106771 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://ics-cert.us-cert.gov/advisories/ICSA-19-029-02 | Third Party AdvisoryUS Government Resource | |
| https://www.cisa.gov/news-events/ics-advisories/icsa-19-029-02 | x_refsource_MISC |
Change history (0)
No recorded changes yet.