CERT-In Vulnerability Note
CIVN-2023-0386
Multiple Vulnerabilities in Mitsubishi Electric FA products
Original Issue Date:December 26, 2023
Severity Rating: CRITICAL
Software Affected
- GT SoftGOT2000 versions 1.275M to 1.290C
- OPC UA data collector SW1DND-DCOPCUA-M & SW1DND-DCOPCUA-MD versions prior to 1.04E
- MX OPC Server UA (Software packaged with MC Works64) SW4DND-MCWDV-MT, etc version 3.05F and later (Packaged with MC Works64 Version 4.03D and later.)
- OPC UA server unit RD81OPC96 all versions
- FX5-OPC versions prior to 1.006
Overview
Multiple vulnerabilities have been reported in the Mitsubishi Electric FA products which could be exploited by an attacker to obtain sensitive information or can cause denial of service condition on the targeted system.
Description
Multiple vulnerabilities exist in Mitsubishi Electric FA products due to observable timing discrepancy in RSA decryption implementations, double Free error when reading a PEM file and Type Confusion error related to X.400 address processing inside an X.509 GeneralName. An attacker could exploit these vulnerabilities by sending a specially crafted request.
Successful exploitation of these vulnerabilities could allow an attacker to obtain sensitive information or can cause denial of service condition on the targeted system.
Solution
Apply appropriate fix/patches as mentioned:
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-018_en.pdf
Vendor Information
Mitsubishi
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-018_en.pdf
References
Mitsubishi
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-018_en.pdf
CVE Name
CVE-2022-4304
CVE-2022-4450
CVE-2023-0286
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|