← Back to home
ICSA-23-103-15  ·  Published 2023-04-14  ·  View on CISA ICS-CERT ↗

Mitsubishi Electric GOC35 Series

CVSS 7.5 HIGH

Risk Summary

Successful exploitation of this vulnerability could lead to a communication error and may result in a denial-of-service condition.

CVEs (1)

Remediations

  • Mitsubishi Electric India has released the following countermeasure/mitigation:
  • The firmware of Extension unit GC-ENET-COM where the first 2 digits of the 11-digit serial number starting with “17” have been fixed. The firmware update in Extension unit GC-ENET-COM is only available from the vendor. Users should contact a local Mitsubishi Electric India representative.
  • Mitsubishi Electric India recommends users take the following mitigations to minimize the risk of attackers exploiting this vulnerability if the mentioned countermeasures cannot be implemented.
  • Use a firewall, virtual private network (VPN), etc. to prevent unauthorized access when internet access is required.
  • Locate control system networks and remote devices behind firewalls and isolate them from the business network to restrict access from untrusted networks and hosts.
  • Restrict physical access to your computer and network equipment on the same network.

Affected Vendors

Mitsubishi Electric India

Affected Products (1)

Mitsubishi Electric India · Mitsubishi Electric India GC-ENET-COM 16XXXXXXXXX.

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more