VDB
ICSA-23-122-01
ICSA-23-122-01
PUBLISHED
CVSS 6.5 MEDIUM
Successful exploitation of these vulnerabilities could allow a malicious attacker to escalate privileges, disclose parameter information in the affected products, and cause a denial-of-service condition.
Risk Scores
CVSS 3.1
6.5
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| MELIPC MI1002-W: * | ||
| MELSEC iQ-R R102WCPU-W: * | ||
| MELSEC Q Q24DHCCPU-VG: * | ||
| MELIPC MI5122-VM: * | ||
| MELIPC MI3315G-W: * | ||
| MELIPC MI2012-W: * | ||
| MELSEC Q Q24DHCCPU-LS: * | ||
| MELIPC MI3321G-W: * | ||
| MELSEC Q Q24DHCCPU-V: * | ||
| MELSEC Q Q26DHCCPU-LS: * |
Timeline
- May 2, 2023 CVE Published
References
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2023/icsa-23-122-01.json advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-122-01 advisory
- https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf url
- https://www.cisa.gov/uscert/ncas/tips/ST04-014 url
- https://us-cert.cisa.gov/ics/Recommended-Practices url
- https://cisa.gov/ics url
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00598.html?wapkw=CVE-2022-0002 fix
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00609.html?wapkw=CVE-2021-33150 fix
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00532.html?wapkw=CVE-2021-0127 fix
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00516.html fix
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00528.html fix
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00464.html?wapkw=CVE-2020-24512 fix
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-001_en.pdf fix
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00463.html?wapkw=CVE-2020-8670 fix
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00442.html?wapkw=CVE-2020-24489 fix