HIGH
Denial-of-Service Vulnerability in Ethernet port on MELSEC iQ-F Ethernet Module and EtherNet/IP Module
Published Nov 19, 2024
7.5
HIGHCVSS 3.1
EPSS 0.68%
Description
Improper Validation of Specified Type of Input vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET versions 1.100 to 1.200 and FX5-ENET/IP versions 1.100 to 1.104 allows a remote attacker to cause a Denial of Service condition in Ethernet communication of the products by sending specially crafted SLMP packets.
Affected products
-
- Version 1.100 to 1.200StatusaffectedConstraints-
- Version
-
- Version 1.100 to 1.104StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mitsubishi Electric Corporation | MELSEC iQ-F Series FX5-ENET | unaffected |
| ||||||
| Mitsubishi Electric Corporation | MELSEC iQ-F Series FX5-ENET/IP | unaffected |
|
No data.
-
- Version 1.100StatusaffectedConstraints<=*
- Version
-
- Version 1.100StatusaffectedConstraints<=1.104
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mitsubishi Electric | Melsec IQ-F Series Fx5-Enet | n/a |
| ||||||
| Mitsubishi Electric | Melsec IQ-F Series Fx5-Enet IP | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49627 Advisory
- https://jvn.jp/vu/JVNVU97790713/ government-resource
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-324-01 government-resource
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-009_en.pdf vendor-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49627 | Advisory | |
| https://jvn.jp/vu/JVNVU97790713/ | government-resource | |
| https://www.cisa.gov/news-events/ics-advisories/icsa-24-324-01 | government-resource | |
| https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-009_en.pdf | vendor-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mitsubishi
Published Nov 19, 2024
Updated Mar 31, 2026
Reserved Sep 4, 2024
Link CVE-2024-8403
CISA Vulnrichment
Updated Nov 19, 2024
ENISA EUVD
EUVD-2024-49627 Assigner Mitsubishi
Published Nov 19, 2024
Updated Mar 31, 2026
Exploited since n/a
Link EUVD-2024-49627