Improper Validation of Specified Type of Input vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET versions 1.100 and later and FX5-ENET/IP versions 1.100 to 1.104 allows a remote attacker to cause a Denial of Service condition in Ethernet communication of the products by sending specially crafted SLMP packets.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-49627 Improper Validation of Specified Type of Input vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET versions 1.100 and later and FX5-ENET/IP versions 1.100 to 1.104 allows a remote attacker to cause a Denial of Service condition in Ethernet communication of the products by sending specially crafted SLMP packets.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 20 Nov 2024 00:45:00 +0000

Type Values Removed Values Added
References

Tue, 19 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Mitsubishi Electric
Mitsubishi Electric melsec Iq-f Series Fx5-enet
Mitsubishi Electric melsec Iq-f Series Fx5-enet Ip
CPEs cpe:2.3:h:mitsubishi_electric:melsec_iq-f_series_fx5-enet:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi_electric:melsec_iq-f_series_fx5-enet_ip:*:*:*:*:*:*:*:*
Vendors & Products Mitsubishi Electric
Mitsubishi Electric melsec Iq-f Series Fx5-enet
Mitsubishi Electric melsec Iq-f Series Fx5-enet Ip
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 19 Nov 2024 06:00:00 +0000

Type Values Removed Values Added
Description Improper Validation of Specified Type of Input vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET versions 1.100 and later and FX5-ENET/IP versions 1.100 to 1.104 allows a remote attacker to cause a Denial of Service condition in Ethernet communication of the products by sending specially crafted SLMP packets.
Title Denial-of-Service Vulnerability in Ethernet port on MELSEC iQ-F Ethernet Module and EtherNet/IP Module
Weaknesses CWE-1287
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mitsubishi

Published:

Updated: 2025-01-06T17:52:58.969Z

Reserved: 2024-09-04T02:53:48.367Z

Link: CVE-2024-8403

cve-icon Vulnrichment

Updated: 2024-11-19T14:28:52.730Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-19T06:15:17.873

Modified: 2024-11-20T01:15:04.303

Link: CVE-2024-8403

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.