Vulnerabilidades em Mitsubishi Electric Corporation

126 resultados
Análise Vexday

Com 125 CVEs catalogadas, o portfólio de vulnerabilidades da Mitsubishi Electric Corporation apresenta taxa de exploração ativa abaixo da média geral do catálogo CISA KEV, sem nenhum registro confirmado de exploração em ambiente real. Ainda assim, 18 vulnerabilidades de severidade crítica merecem atenção, especialmente considerando que o tipo de falha mais frequente é CWE-306 — ausência de autenticação para função crítica —, padrão que historicamente representa risco elevado em ambientes de tecnologia operacional e sistemas de controle industrial. A CVE mais perigosa atualmente monitorada, CVE-2020-5666, registra EPSS de 0,084, indicando probabilidade de exploração ainda moderada, mas seu contexto de origem reforça a necessidade de rastreamento contínuo. A ausência de PoCs públicas reduz a superfície de ameaça imediata, porém as 5 CVEs surgidas nos últimos 90 dias sinalizam que o ritmo de descoberta de novas falhas permanece ativo e deve ser acompanhado de perto por equipes de segurança em ambientes críticos.

CVE-2020-5666Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '05' to '19' and R04/EPSS 8.4%CVE-2021-20588HIGHImproper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging ConfiguEPSS 6.9%CVE-2020-5668Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series modules (R00/01/02CPU firmware version '19' and earlier, R04/08/16/32/EPSS 4.7%CVE-2020-5644Buffer overflow vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE CoreOS version "05.EPSS 4.5%CVE-2020-5647Improper access control vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE CoreOS versEPSS 4.2%CVE-2020-5646NULL pointer dereferences vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE CoreOS veEPSS 4.2%CVE-2020-5649Resource management error vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE CoreOS veEPSS 4.1%CVE-2021-20587HIGHHeap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.11EPSS 3.9%CVE-2020-5645Session fixation vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE CoreOS version "05EPSS 3.9%CVE-2020-5652Uncontrolled resource consumption vulnerability in Ethernet Port on MELSEC iQ-R, Q and L series CPU modules (R 00/01/02 CPU firmware versionEPSS 3.6%CVE-2020-5599TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, EPSS 3.5%CVE-2020-5648Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in TCP/IP function included in the firmwareEPSS 3.5%CVE-2023-1424CRITICALDenial-of-Service and Remote Code Execution Vulnerability in MELSEC Series CPU moduleEPSS 3.4%CVE-2020-5653Buffer overflow vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network Interface ModEPSS 3.2%CVE-2021-20610HIGHImproper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R SeriesEPSS 3.1%CVE-2021-20609HIGHUncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EPSS 3.1%CVE-2021-20611HIGHImproper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, EPSS 3.0%CVE-2020-5656Improper access control vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network InterEPSS 3.0%CVE-2020-5655NULL pointer dereferences vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network IntEPSS 2.9%CVE-2020-5658Resource Management Errors vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network InEPSS 2.9%