← Back to home
ICSA-23-208-03  ·  Published 2024-01-30  ·  View on CISA ICS-CERT ↗

Mitsubishi Electric CNC Series (Update E)

CVSS 9.8 CRITICAL

Risk Summary

Successful exploitation of this vulnerability could allow a malicious remote attacker to cause a denial-of-service condition and execute malicious code on the product by sending specially crafted packets. System reset is required for recovery.

CVEs (1)

Remediations

  • Mitsubishi Electric has provided a fix for the following products:
  • M800VW (BND-2051W000-**): Versions A9 or later
  • M800VS (BND-2052W000-**): Versions A9 or later
  • M80V (BND-2053W000-**): Versions A9 or later
  • M80VW (BND-2054W000-**): Versions A9 or later
  • M800W (BND-2005W000-**): Versions FC or later
  • M800S (BND-2006W000-**): Versions FC or later
  • M80 (BND-2007W000-**): Versions FC or later
  • M80W (BND-2008W000-**): Versions FC or later
  • E80 (BND-2009W000-**): Versions FC or later
  • C80 (BND-2036W000-**): Versions BG or later
  • M750VW (BND-1015W002-**): Versions LG or later
  • M730VW/M720VW (BND-1015W000-**): Versions LG or later
  • M750VS (BND-1012W002-**): Versions LG or later
  • M730VS/M720VS (BND-1012W000-**): Versions LG or later
  • M70V (BND-1018W000-**): Versions LG or later
  • E70 (BND-1022W000-**): Versions LG or later
  • Remote Service Gateway Unit (BND-2041W001-**): Versions AE or later
  • For specific update instructions and additional details refer to Mitsubishi Electric advisory 2023-007.
  • For users that are unable to update their systems immediately, Mitsubishi Electric recommends applying the mitigations below to minimize the risk:
  • Use a firewall or virtual private network (VPN), etc. to prevent unauthorized access when Internet access is required.
  • Install anti-virus software on the PC that can access the product.
  • Use within a LAN and block access from untrusted networks and hosts through firewalls.
  • Restrict physical access to the affected product and the LAN to which the product is connected.

Affected Vendors

Mitsubishi Electric

Affected Products (18)

Mitsubishi Electric · M800VW (BND-2051W000-**) <=A8
Mitsubishi Electric · M800VS (BND-2052W000-**) <=A8
Mitsubishi Electric · M80V (BND-2053W000-**) <=A8
Mitsubishi Electric · M80VW (BND-2054W000-**) <=A8
Mitsubishi Electric · M800W (BND-2005W000-**) <=FB
Mitsubishi Electric · M800S (BND-2006W000-**) <=FB
Mitsubishi Electric · M80 (BND-2007W000-**) <=FB
Mitsubishi Electric · M80W (BND-2008W000-**) <=FB
Mitsubishi Electric · E80 (BND-2009W000-**) <=FB
Mitsubishi Electric · C80 (BND-2036W000-**) <=BF
Mitsubishi Electric · M750VW (BND-1015W002-**) <=LF
Mitsubishi Electric · M730VW/M720VW (BND-1015W000-**) <=LF
Mitsubishi Electric · M750VS (BND-1012W002-**) <=LF
Mitsubishi Electric · M730VS/M720VS (BND-1012W000-**) <=LF
Mitsubishi Electric · M70V (BND-1018W000-**) <=LF
Mitsubishi Electric · E70 (BND-1022W000-**) <=LF
Mitsubishi Electric · Remote Service Gateway Unit (BND-2041W001-**) <=AD
Mitsubishi Electric · Data Acquisition Unit (BND-2041W002-**) vers:all/*

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more