Vulnerabilidades em Mitsubishi Electric Corporation

126 resultados
Análise Vexday

Com 125 CVEs catalogadas, o portfólio de vulnerabilidades da Mitsubishi Electric Corporation apresenta taxa de exploração ativa abaixo da média geral do catálogo CISA KEV, sem nenhum registro confirmado de exploração em ambiente real. Ainda assim, 18 vulnerabilidades de severidade crítica merecem atenção, especialmente considerando que o tipo de falha mais frequente é CWE-306 — ausência de autenticação para função crítica —, padrão que historicamente representa risco elevado em ambientes de tecnologia operacional e sistemas de controle industrial. A CVE mais perigosa atualmente monitorada, CVE-2020-5666, registra EPSS de 0,084, indicando probabilidade de exploração ainda moderada, mas seu contexto de origem reforça a necessidade de rastreamento contínuo. A ausência de PoCs públicas reduz a superfície de ameaça imediata, porém as 5 CVEs surgidas nos últimos 90 dias sinalizam que o ritmo de descoberta de novas falhas permanece ativo e deve ser acompanhado de perto por equipes de segurança em ambientes críticos.

CVE-2020-5675Out-of-bounds read vulnerability in GT21 model of GOT2000 series (GT2107-WTBD V01.39.000 and earlier, GT2107-WTSD V01.39.000 and earlier, GTEPSS 2.8%CVE-2020-5654Session fixation vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network Interface MoEPSS 2.7%CVE-2020-5595TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, EPSS 2.5%CVE-2020-5544Null Pointer Dereference vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmwareEPSS 2.4%CVE-2020-5545TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows remote aEPSS 2.3%CVE-2020-5547Resource Management Errors vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmwaEPSS 2.3%CVE-2020-5542Buffer error vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0EPSS 2.3%CVE-2020-5543TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not properEPSS 2.1%CVE-2023-6943CRITICALUse of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocketEPSS 2.1%CVE-2023-3346CRITICALDenial of Service (DoS) and Remote Code Execution Vulnerability in MITSUBISHI CNC SeriesEPSS 2.1%CVE-2020-5597TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, EPSS 2.0%CVE-2020-5531Mitsubishi Electric MELSEC C Controller Module and MELIPC Series MI5000 MELSEC-Q Series C Controller Module(Q24DHCCPU-V, Q24DHCCPU-VG User EEPSS 2.0%CVE-2020-5600TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, EPSS 2.0%CVE-2020-5598TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, EPSS 1.8%CVE-2022-33324HIGHDenial-of-Service Vulnerability in Ethernet port of MELSEC iQ-R, iQ-L Series and MELIPC SeriesEPSS 1.7%CVE-2020-5596TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, EPSS 1.6%CVE-2020-5602Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and EPSS 1.4%CVE-2020-5603Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. EPSS 1.3%CVE-2020-5527When MELSOFT transmission port (UDP/IP) of Mitsubishi Electric MELSEC iQ-R series (all versions), MELSEC iQ-F series (all versions), MELSEC EPSS 1.3%CVE-2023-2846HIGHAuthentication Bypass Vulnerability in MELSEC-F Series main moduleEPSS 1.3%