ICSA-23-103-15
·
Published 2023-04-14
·
View on CISA ICS-CERT ↗
Mitsubishi Electric GOC35 Series
CVSS 7.5
HIGH
Risk Summary
Successful exploitation of this vulnerability could lead to a communication error and may result in a denial-of-service condition.
CVEs (1)
Remediations
- Mitsubishi Electric India has released the following countermeasure/mitigation:
- The firmware of Extension unit GC-ENET-COM where the first 2 digits of the 11-digit serial number starting with “17” have been fixed. The firmware update in Extension unit GC-ENET-COM is only available from the vendor. Users should contact a local Mitsubishi Electric India representative.
- Mitsubishi Electric India recommends users take the following mitigations to minimize the risk of attackers exploiting this vulnerability if the mentioned countermeasures cannot be implemented.
- Use a firewall, virtual private network (VPN), etc. to prevent unauthorized access when internet access is required.
- Locate control system networks and remote devices behind firewalls and isolate them from the business network to restrict access from untrusted networks and hosts.
- Restrict physical access to your computer and network equipment on the same network.
Affected Vendors
Mitsubishi Electric India
Affected Products (1)
Mitsubishi Electric India
·
Mitsubishi Electric India GC-ENET-COM
16XXXXXXXXX.
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more