CVE-2023-3346
Published: Aug 3, 2023
Modified: Dec 4, 2024
CVSS v3.1
9.8
Description
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition and execute arbitrary code on the product by sending specially crafted packets. In addition, system reset is required for recovery.
| Vendor | Product | Versions |
|---|---|---|
Mitsubishi Electric Corporation | MITSUBISHI CNC M800V Series M800VW | affected System Number BND-2051W000 versions A8 and prior |
Mitsubishi Electric Corporation | MITSUBISHI CNC M800V Series M800VS | affected System Number BND-2052W000 versions A8 and prior |
Mitsubishi Electric Corporation | MITSUBISHI CNC M80V Series M80V | affected System Number BND-2053W000 versions A8 and prior |
Mitsubishi Electric Corporation | MITSUBISHI CNC M80V Series M80VW | affected System Number BND-2054W000 versions A8 and prior |
Mitsubishi Electric Corporation | MITSUBISHI CNC M800 Series M800W | affected System Number BND-2005W000 versions FB and prior |
Mitsubishi Electric Corporation | MITSUBISHI CNC M800 Series M800S | affected System Number BND-2006W000 versions FB and prior |
Mitsubishi Electric Corporation | MITSUBISHI CNC M80 Series M80 | affected System Number BND-2007W000 versions FB and prior |
Mitsubishi Electric Corporation | MITSUBISHI CNC M80 Series M80W | affected System Number BND-2008W000 versions FB and prior |
Mitsubishi Electric Corporation | MITSUBISHI CNC E80 Series E80 | affected System Number BND-2009W000 versions FB and prior |
Mitsubishi Electric Corporation | MITSUBISHI CNC C80 Series C80 | affected System Number BND-2036W000 versions BF and prior |
Mitsubishi Electric Corporation | MITSUBISHI CNC M700V Series M720VW | affected System Number BND-1015W000 versions LF and prior |
Mitsubishi Electric Corporation | MITSUBISHI CNC M700V Series M730VW | affected System Number BND-1015W000 versions LF and prior |
Mitsubishi Electric Corporation | MITSUBISHI CNC M700V Series M750VW | affected System Number BND-1015W002 versions LF and prior |
Mitsubishi Electric Corporation | MITSUBISHI CNC M700V Series M720VS | affected System Number BND-1012W000 versions LF and prior |
Mitsubishi Electric Corporation | MITSUBISHI CNC M700V Series M730VS | affected System Number BND-1012W000 versions LF and prior |
Mitsubishi Electric Corporation | MITSUBISHI CNC M700V Series M750VS | affected System Number BND-1012W002 versions LF and prior |
Mitsubishi Electric Corporation | MITSUBISHI CNC M70V Series M70V | affected System Number BND-1018W000 versions LF and prior |
Mitsubishi Electric Corporation | MITSUBISHI CNC E70 Series E70 | affected System Number BND-1022W000 versions LF and prior |
Mitsubishi Electric Corporation | MITSUBISHI CNC IoT Unit Remote Service Gateway Unit | affected System Number BND-2041W001 versions AD and prior |
Mitsubishi Electric Corporation | MITSUBISHI CNC IoT Unit Data Acquisition Unit | affected System Number BND-2041W002 all versions |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now