ICSA-23-208-03
·
Published 2024-01-30
·
View on CISA ICS-CERT ↗
Mitsubishi Electric CNC Series (Update E)
CVSS 9.8
CRITICAL
Risk Summary
Successful exploitation of this vulnerability could allow a malicious remote attacker to cause a denial-of-service condition and execute malicious code on the product by sending specially crafted packets. System reset is required for recovery.
CVEs (1)
Remediations
- Mitsubishi Electric has provided a fix for the following products:
- M800VW (BND-2051W000-**): Versions A9 or later
- M800VS (BND-2052W000-**): Versions A9 or later
- M80V (BND-2053W000-**): Versions A9 or later
- M80VW (BND-2054W000-**): Versions A9 or later
- M800W (BND-2005W000-**): Versions FC or later
- M800S (BND-2006W000-**): Versions FC or later
- M80 (BND-2007W000-**): Versions FC or later
- M80W (BND-2008W000-**): Versions FC or later
- E80 (BND-2009W000-**): Versions FC or later
- C80 (BND-2036W000-**): Versions BG or later
- M750VW (BND-1015W002-**): Versions LG or later
- M730VW/M720VW (BND-1015W000-**): Versions LG or later
- M750VS (BND-1012W002-**): Versions LG or later
- M730VS/M720VS (BND-1012W000-**): Versions LG or later
- M70V (BND-1018W000-**): Versions LG or later
- E70 (BND-1022W000-**): Versions LG or later
- Remote Service Gateway Unit (BND-2041W001-**): Versions AE or later
- For specific update instructions and additional details refer to Mitsubishi Electric advisory 2023-007.
- For users that are unable to update their systems immediately, Mitsubishi Electric recommends applying the mitigations below to minimize the risk:
- Use a firewall or virtual private network (VPN), etc. to prevent unauthorized access when Internet access is required.
- Install anti-virus software on the PC that can access the product.
- Use within a LAN and block access from untrusted networks and hosts through firewalls.
- Restrict physical access to the affected product and the LAN to which the product is connected.
Affected Vendors
Mitsubishi Electric
Affected Products (18)
Mitsubishi Electric
·
M800VW (BND-2051W000-**)
<=A8
Mitsubishi Electric
·
M800VS (BND-2052W000-**)
<=A8
Mitsubishi Electric
·
M80V (BND-2053W000-**)
<=A8
Mitsubishi Electric
·
M80VW (BND-2054W000-**)
<=A8
Mitsubishi Electric
·
M800W (BND-2005W000-**)
<=FB
Mitsubishi Electric
·
M800S (BND-2006W000-**)
<=FB
Mitsubishi Electric
·
M80 (BND-2007W000-**)
<=FB
Mitsubishi Electric
·
M80W (BND-2008W000-**)
<=FB
Mitsubishi Electric
·
E80 (BND-2009W000-**)
<=FB
Mitsubishi Electric
·
C80 (BND-2036W000-**)
<=BF
Mitsubishi Electric
·
M750VW (BND-1015W002-**)
<=LF
Mitsubishi Electric
·
M730VW/M720VW (BND-1015W000-**)
<=LF
Mitsubishi Electric
·
M750VS (BND-1012W002-**)
<=LF
Mitsubishi Electric
·
M730VS/M720VS (BND-1012W000-**)
<=LF
Mitsubishi Electric
·
M70V (BND-1018W000-**)
<=LF
Mitsubishi Electric
·
E70 (BND-1022W000-**)
<=LF
Mitsubishi Electric
·
Remote Service Gateway Unit (BND-2041W001-**)
<=AD
Mitsubishi Electric
·
Data Acquisition Unit (BND-2041W002-**)
vers:all/*
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more