Predictable Seed in Pseudo-Random Number Generator (PRNG) vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U-xMy/z (x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 17X**** or later, and versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U-xMy/z (x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 179**** and prior, and versions 1.074 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-xMy/z (x=32,64,96, y=T, z=D,DSS)) with serial number 17X**** or later, and versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-xMy/z (x=32,64,96, y=T, z=D,DSS)) with serial number 179**** and prior, and versions 1.074 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-32MT/DS-TS versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-32MT/DSS-TS versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UJ-xMy/z (x=24,40,60, y=T,R, z=ES,ESS) versions 1.042 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UJ-xMy/ES-A (x=24,40,60, y=T,R) versions 1.043 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5S-xMy/z (x=30,40,60,80, y=T,R, z=ES,ESS) versions 1.003 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-32MR/DS-TS versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R00/01/02CPU versions 33 and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120(EN)CPU versions 66 and prior allows a remote unauthenticated attacker to access the Web server function by guessing the random numbers used for authentication from several used random numbers.

Project Subscriptions

Vendors Products
Mitsubishielectric Subscribe
Fx5s-30mr\/es Subscribe
Fx5s-30mr\/es Firmware Subscribe
Fx5s-30mt\/es Subscribe
Fx5s-30mt\/es Firmware Subscribe
Fx5s-30mt\/ess Subscribe
Fx5s-30mt\/ess Firmware Subscribe
Fx5s-40mr\/es Subscribe
Fx5s-40mr\/es Firmware Subscribe
Fx5s-40mt\/es Subscribe
Fx5s-40mt\/es Firmware Subscribe
Fx5s-40mt\/ess Subscribe
Fx5s-40mt\/ess Firmware Subscribe
Fx5s-60mr\/es Subscribe
Fx5s-60mr\/es Firmware Subscribe
Fx5s-60mt\/es Subscribe
Fx5s-60mt\/es Firmware Subscribe
Fx5s-60mt\/ess Subscribe
Fx5s-60mt\/ess Firmware Subscribe
Fx5s-80mr\/es Subscribe
Fx5s-80mr\/es Firmware Subscribe
Fx5s-80mt\/es Subscribe
Fx5s-80mt\/es Firmware Subscribe
Fx5s-80mt\/ess Subscribe
Fx5s-80mt\/ess Firmware Subscribe
Fx5u-32mt\/dss Subscribe
Fx5u-32mt\/dss Firmware Subscribe
Fx5u-64mt\/dss Subscribe
Fx5u-64mt\/dss Firmware Subscribe
Fx5u-80mt\/dss Subscribe
Fx5u-80mt\/dss Firmware Subscribe
Fx5u-80mt\/ess Subscribe
Fx5u-80mt\/ess Firmware Subscribe
Fx5uc-32mr\/ds-ts Subscribe
Fx5uc-32mr\/ds-ts Firmware Subscribe
Fx5uc-32mt\/d Subscribe
Fx5uc-32mt\/d Firmware Subscribe
Fx5uc-32mt\/ds-ts Subscribe
Fx5uc-32mt\/ds-ts Firmware Subscribe
Fx5uc-32mt\/dss Subscribe
Fx5uc-32mt\/dss-ts Subscribe
Fx5uc-32mt\/dss-ts Firmware Subscribe
Fx5uc-32mt\/dss Firmware Subscribe
Fx5uc-64mt\/d Subscribe
Fx5uc-64mt\/d Firmware Subscribe
Fx5uc-64mt\/dss Subscribe
Fx5uc-64mt\/dss Firmware Subscribe
Fx5uc-96mt\/d Subscribe
Fx5uc-96mt\/d Firmware Subscribe
Fx5uc-96mt\/dss Subscribe
Fx5uc-96mt\/dss Firmware Subscribe
Fx5uj-24mr\/es Subscribe
Fx5uj-24mr\/es-a Subscribe
Fx5uj-24mr\/es-a Firmware Subscribe
Fx5uj-24mr\/es Firmware Subscribe
Fx5uj-24mt\/es Subscribe
Fx5uj-24mt\/es-a Subscribe
Fx5uj-24mt\/es-a Firmware Subscribe
Fx5uj-24mt\/es Firmware Subscribe
Fx5uj-24mt\/ess Subscribe
Fx5uj-24mt\/ess Firmware Subscribe
Fx5uj-40mr\/es Subscribe
Fx5uj-40mr\/es-a Subscribe
Fx5uj-40mr\/es-a Firmware Subscribe
Fx5uj-40mr\/es Firmware Subscribe
Fx5uj-40mt\/es Subscribe
Fx5uj-40mt\/es-a Subscribe
Fx5uj-40mt\/es-a Firmware Subscribe
Fx5uj-40mt\/es Firmware Subscribe
Fx5uj-40mt\/ess Subscribe
Fx5uj-40mt\/ess Firmware Subscribe
Fx5uj-60mr\/es Subscribe
Fx5uj-60mr\/es-a Subscribe
Fx5uj-60mr\/es-a Firmware Subscribe
Fx5uj-60mr\/es Firmware Subscribe
Fx5uj-60mt\/es Subscribe
Fx5uj-60mt\/es-a Subscribe
Fx5uj-60mt\/es-a Firmware Subscribe
Fx5uj-60mt\/es Firmware Subscribe
Fx5uj-60mt\/ess Subscribe
Fx5uj-60mt\/ess Firmware Subscribe
R00cpu Firmware Subscribe
R01cpu Firmware Subscribe
R02cpu Firmware Subscribe
R04cpu Firmware Subscribe
R04encpu Subscribe
R04encpu Firmware Subscribe
R08cpu Firmware Subscribe
R08encpu Subscribe
R08encpu Firmware Subscribe
R120cpu Subscribe
R120cpu Firmware Subscribe
R120encpu Subscribe
R120encpu Firmware Subscribe
R16cpu Firmware Subscribe
R16encpu Subscribe
R16encpu Firmware Subscribe
R32cpu Firmware Subscribe
R32encpu Subscribe
R32encpu Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-43565 Predictable Seed in Pseudo-Random Number Generator (PRNG) vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U-xMy/z (x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 17X**** or later, and versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U-xMy/z (x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 179**** and prior, and versions 1.074 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-xMy/z (x=32,64,96, y=T, z=D,DSS)) with serial number 17X**** or later, and versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-xMy/z (x=32,64,96, y=T, z=D,DSS)) with serial number 179**** and prior, and versions 1.074 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-32MT/DS-TS versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-32MT/DSS-TS versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UJ-xMy/z (x=24,40,60, y=T,R, z=ES,ESS) versions 1.042 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UJ-xMy/ES-A (x=24,40,60, y=T,R) versions 1.043 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5S-xMy/z (x=30,40,60,80, y=T,R, z=ES,ESS) versions 1.003 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-32MR/DS-TS versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R00/01/02CPU versions 33 and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120(EN)CPU versions 66 and prior allows a remote unauthenticated attacker to access the Web server function by guessing the random numbers used for authentication from several used random numbers.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mitsubishi

Published:

Updated: 2024-08-03T12:14:39.972Z

Reserved: 2022-09-08T19:40:16.931Z

Link: CVE-2022-40267

cve-icon Vulnrichment

Updated: 2024-08-03T12:14:39.972Z

cve-icon NVD

Status : Modified

Published: 2023-01-20T08:15:11.373

Modified: 2024-11-21T07:21:09.770

Link: CVE-2022-40267

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses