← Back to home
ICSA-21-287-03  ·  Published 2024-04-18  ·  View on CISA ICS-CERT ↗

Mitsubishi Electric MELSEC iQ-R Series

CVSS 9.1 CRITICAL

Risk Summary

Successful exploitation of this vulnerability could allow a remote attacker to be able to log in to the CPU module by obtaining credentials.

CVEs (1)

Remediations

  • Mitsubishi Electric has prepared the following countermeasures:
  • MELSEC iQ-R series Safety CPU R08/16/32/120SFCPU: Firmware versions "27" or later
  • MELSEC iQ-R series SIL2 Process CPU R08/16/32/120PSFCPU: Firmware versions "12" or later
  • Customers using the affected products and versions may take measures through mitigations and workarounds. Mitsubishi Electric has released the fixed version as shown above, but updating the product to the fixed version is not available. Mitsubishi Electric recommends users take the following mitigation measures to minimize risk associated with this vulnerability:
  • Use a firewall or virtual private network (VPN) to prevent unauthorized access when Internet access is required.
  • Use within a LAN and block access from untrusted networks and hosts through firewalls.
  • Use the IP filter function to restrict the accessible IP addresses.
  • Please refer to the Mitsubishi Electric advisory for further details.

Affected Vendors

Mitsubishi Electric Corporation

Affected Products (8)

Mitsubishi Electric Corporation · MELSEC iQ-R series Safety CPU R08SFCPU Firmware <=26
Mitsubishi Electric Corporation · MELSEC iQ-R series Safety CPU R16SFCPU Firmware <=26
Mitsubishi Electric Corporation · MELSEC iQ-R series Safety CPU R32SFCPU Firmware <=26
Mitsubishi Electric Corporation · MELSEC iQ-R series Safety CPU R120SFCPU Firmware <=26
Mitsubishi Electric Corporation · MELSEC iQ-R series SIL2 Process CPU R08PSFCPU Firmware <=11
Mitsubishi Electric Corporation · MELSEC iQ-R series SIL2 Process CPU R16PSFCPU Firmware <=11
Mitsubishi Electric Corporation · MELSEC iQ-R series SIL2 Process CPU R32PSFCPU Firmware <=11
Mitsubishi Electric Corporation · MELSEC iQ-R series SIL2 Process CPU R120PSFCPU Firmware <=11

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more