Active Debug Code vulnerability in robot controller of Mitsubishi Electric Corporation industrial robot MELFA SD/SQ Series and MELFA F-Series allows a remote unauthenticated attacker to gain unauthorized access by authentication bypass through an unauthorized telnet login. As for the affected model names, controller types and firmware versions, see the Mitsubishi Electric's advisory which is listed in [References] section.

Project Subscriptions

Vendors Products
Mitsubishielectric Subscribe
Rh-12fh55 Subscribe
Rh-12fh55 Firmware Subscribe
Rh-12fh70 Subscribe
Rh-12fh70 Firmware Subscribe
Rh-12fh85 Subscribe
Rh-12fh85 Firmware Subscribe
Rh-12sdh55 Subscribe
Rh-12sdh55 Firmware Subscribe
Rh-12sdh70 Subscribe
Rh-12sdh70 Firmware Subscribe
Rh-12sdh85 Subscribe
Rh-12sdh85 Firmware Subscribe
Rh-12sqh55 Subscribe
Rh-12sqh55 Firmware Subscribe
Rh-12sqh70 Subscribe
Rh-12sqh70 Firmware Subscribe
Rh-12sqh85 Subscribe
Rh-12sqh85 Firmware Subscribe
Rh-20fh100 Subscribe
Rh-20fh100 Firmware Subscribe
Rh-20fh85 Subscribe
Rh-20fh85 Firmware Subscribe
Rh-20sdh100 Subscribe
Rh-20sdh100 Firmware Subscribe
Rh-20sdh85 Subscribe
Rh-20sdh85 Firmware Subscribe
Rh-20sqh85 Subscribe
Rh-20sqh85 Firmware Subscribe
Rh-3fh35 Subscribe
Rh-3fh35 Firmware Subscribe
Rh-3fh45 Subscribe
Rh-3fh45 Firmware Subscribe
Rh-3fh55 Subscribe
Rh-3fh55 Firmware Subscribe
Rh-3sdhr Subscribe
Rh-3sdhr Firmware Subscribe
Rh-3sqhr Subscribe
Rh-3sqhr Firmware Subscribe
Rh-6fh35 Subscribe
Rh-6fh35 Firmware Subscribe
Rh-6fh45 Subscribe
Rh-6fh45 Firmware Subscribe
Rh-6fh55 Subscribe
Rh-6fh55 Firmware Subscribe
Rh-6sdh35 Subscribe
Rh-6sdh35 Firmware Subscribe
Rh-6sdh45 Subscribe
Rh-6sdh45 Firmware Subscribe
Rh-6sdh55 Subscribe
Rh-6sdh55 Firmware Subscribe
Rh-6sqh35 Subscribe
Rh-6sqh35 Firmware Subscribe
Rh-6sqh45 Subscribe
Rh-6sqh45 Firmware Subscribe
Rh-6sqh55 Subscribe
Rh-6sqh55 Firmware Subscribe
Rv-12sd Subscribe
Rv-12sd Firmware Subscribe
Rv-12sdl Subscribe
Rv-12sdl Firmware Subscribe
Rv-12sq Subscribe
Rv-12sq Firmware Subscribe
Rv-12sql Subscribe
Rv-12sql Firmware Subscribe
Rv-13f Firmware Subscribe
Rv-13fl Subscribe
Rv-13fl Firmware Subscribe
Rv-20f Firmware Subscribe
Rv-2f Firmware Subscribe
Rv-2sdb Subscribe
Rv-2sdb Firmware Subscribe
Rv-2sqb Subscribe
Rv-2sqb Firmware Subscribe
Rv-3sd Firmware Subscribe
Rv-3sdj Subscribe
Rv-3sdj Firmware Subscribe
Rv-3sq Firmware Subscribe
Rv-3sqj Subscribe
Rv-3sqj Firmware Subscribe
Rv-4f Firmware Subscribe
Rv-4fl Firmware Subscribe
Rv-6sd Firmware Subscribe
Rv-6sdl Subscribe
Rv-6sdl Firmware Subscribe
Rv-6sq Firmware Subscribe
Rv-6sql Subscribe
Rv-6sql Firmware Subscribe
Rv-7f Firmware Subscribe
Rv-7fl Firmware Subscribe
Rv-7fll Subscribe
Rv-7fll Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-36366 Active Debug Code vulnerability in robot controller of Mitsubishi Electric Corporation industrial robot MELFA SD/SQ Series and MELFA F-Series allows a remote unauthenticated attacker to gain unauthorized access by authentication bypass through an unauthorized telnet login. As for the affected model names, controller types and firmware versions, see the Mitsubishi Electric's advisory which is listed in [References] section.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 26 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mitsubishi

Published:

Updated: 2025-03-26T18:43:56.420Z

Reserved: 2022-06-14T17:50:53.643Z

Link: CVE-2022-33323

cve-icon Vulnrichment

Updated: 2024-08-03T08:09:21.317Z

cve-icon NVD

Status : Modified

Published: 2023-02-02T06:15:08.393

Modified: 2024-11-21T07:08:11.440

Link: CVE-2022-33323

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses