🛡️ CVE-2022-24946
🟠 CVSS 7.5 — High ✅ No Known Exploit CWE-667 NVD
7.5
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V firmware versions "16" and prior, Mitsubishi Electric MELSEC-Q Series Q03UDECPU the first 5 digits of serial No. "24061" and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/10/13/20/26/50/100UDEHCPU the first 5 digits of serial No. "24061" and prior, Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/13/26UDPVCPU the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-Q Series Q12DCCPU-V all versions, Mitsubishi Electric MELSEC-Q Series Q24DHCCPU-V(G) all versions, Mitsubishi Electric MELSEC-Q Series Q24/26DHCCPU-LS all versions, Mitsubishi Electric MELSEC-L series L02/06/26CPU(-P) the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-L series L26CPU-(P)BT the first 5 digits of serial number "24051" and prior and Mitsubishi Electric MELIPC Series MI5122-VW firmware versions "05" and prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition in Ethernet communications by sending specially crafted packets. A system reset of the products is required for recovery.

Details

Severity HIGH
CVSS Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE CWE-667
Public Exploit ✅ No
Source NVD
Published 2022-06-15
Updated 2026-06-08
Modified 2026-06-02
Fix URL N/A

Affected Packages

Software From version Fixed in
l02cpu-firmware
l02cpu-p-firmware
l02scpu-firmware
l02scpu-p-firmware
l06cpu-firmware
l06cpu-p-firmware
l26cpu-\(p\)bt-firmware
l26cpu-bt-cm-firmware
l26cpu-bt-firmware
l26cpu-firmware
l26cpu-p-firmware
l26cpu-pbt-firmware
q03udecpu-firmware
q04udehcpu-firmware
q04udpvcpu-firmware
q04udvcpu-firmware
q06ccpu-v-firmware
q06phcpu-firmware
q06udehcpu-firmware
q06udpvcpu-firmware
q06udvcpu-firmware
q100udehcpu-firmware
q10udehcpu-firmware
q13udehcpu-firmware
q13udpvcpu-firmware
q13udvcpu-firmware
q20udehcpu-firmware
q26dhccpu-ls-firmware
q26udehcpu-firmware
q26udpvcpu-firmware
q26udvcpu-firmware
q50udehcpu-firmware

Free Vulnerability Check

Is your WordPress site affected?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.