{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-0802","assignerOrgId":"e0f77b61-78fd-4786-b3fb-1ee347a748ad","state":"PUBLISHED","assignerShortName":"Mitsubishi","dateReserved":"2024-01-23T00:04:23.168Z","datePublished":"2024-03-14T23:57:07.390Z","dateUpdated":"2024-08-01T18:18:18.584Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"MELSEC-Q Series Q03UDECPU","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26061\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-Q Series Q04UDEHCPU","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26061\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-Q Series Q06UDEHCPU","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26061\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-Q Series Q10UDEHCPU","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26061\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-Q Series Q13UDEHCPU","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26061\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-Q Series Q20UDEHCPU","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26061\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-Q Series Q26UDEHCPU","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26061\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-Q Series Q50UDEHCPU","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26061\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-Q Series Q100UDEHCPU","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26061\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-Q Series Q03UDVCPU","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26061\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-Q Series Q04UDVCPU","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26061\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-Q Series Q06UDVCPU","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26061\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-Q Series Q13UDVCPU","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26061\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-Q Series Q26UDVCPU","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26061\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-Q Series Q04UDPVCPU","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26061\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-Q Series Q06UDPVCPU","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26061\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-Q Series Q13UDPVCPU","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26061\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-Q Series Q26UDPVCPU","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26061\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-L Series L02CPU","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26041\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-L Series L06CPU","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26041\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-L Series L26CPU","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26041\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-L Series L02CPU-P","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26041\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-L Series L06CPU-P","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26041\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-L Series L26CPU-P","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26041\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-L Series L26CPU-BT","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26041\" and prior"}]},{"defaultStatus":"unaffected","product":"MELSEC-L Series L26CPU-PBT","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"The first 5 digits of serial No. \"26041\" and prior"}]}],"datePublic":"2024-03-14T03:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to read arbitrary information from a target product or execute malicious code on a target product by sending a specially crafted packet."}],"value":"Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to read arbitrary information from a target product or execute malicious code on a target product by sending a specially crafted packet."}],"impacts":[{"descriptions":[{"lang":"en","value":"Information Disclosure and Remote Code Execution"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-468","description":"CWE-468 Incorrect Pointer Scaling","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"e0f77b61-78fd-4786-b3fb-1ee347a748ad","shortName":"Mitsubishi","dateUpdated":"2024-06-14T00:03:03.747Z"},"references":[{"tags":["vendor-advisory"],"url":"https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-024_en.pdf"},{"tags":["government-resource"],"url":"https://jvn.jp/vu/JVNVU99690199/"},{"tags":["government-resource"],"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-24-074-14"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"affected":[{"vendor":"mitsubishielectric","product":"melsec_q-q03udecpu","cpes":["cpe:2.3:h:mitsubishielectric:melsec_q-q03udecpu:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26061","versionType":"custom"}]},{"vendor":"mitsubishielectric","product":"melsec_q-q04udehcpu","cpes":["cpe:2.3:h:mitsubishielectric:melsec_q-q04udehcpu:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26061","versionType":"custom"}]},{"vendor":"mitsubishielectric","product":"melsec_q-q06udehcpu","cpes":["cpe:2.3:h:mitsubishielectric:melsec_q-q06udehcpu:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26061","versionType":"custom"}]},{"vendor":"mitsubishielectric","product":"melsec_q-q10udehcpu","cpes":["cpe:2.3:h:mitsubishielectric:melsec_q-q10udehcpu:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26061","versionType":"custom"}]},{"vendor":"mitsubishielectric","product":"melsec_q-q13udehcpu","cpes":["cpe:2.3:h:mitsubishielectric:melsec_q-q13udehcpu:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26061","versionType":"custom"}]},{"vendor":"mitsubishielectric","product":"melsec_q-q20udehcpu","cpes":["cpe:2.3:h:mitsubishielectric:melsec_q-q20udehcpu:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26061","versionType":"custom"}]},{"vendor":"mitsubishielectric","product":"melsec_q-q26udehcpu","cpes":["cpe:2.3:h:mitsubishielectric:melsec_q-q26udehcpu:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26061","versionType":"custom"}]},{"vendor":"mitsubishielectric","product":"melsec_q-q50udehcpu","cpes":["cpe:2.3:h:mitsubishielectric:melsec_q-q50udehcpu:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26061","versionType":"custom"}]},{"vendor":"mitsubishielectric","product":"melsec_q-q100udehcpu","cpes":["cpe:2.3:h:mitsubishielectric:melsec_q-q100udehcpu:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26061","versionType":"custom"}]},{"vendor":"mitsubishi","product":"melsec_q03udvcpu","cpes":["cpe:2.3:h:mitsubishi:melsec_q03udvcpu:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26061","versionType":"custom"}]},{"vendor":"mitsubishi","product":"melsec_q04udvcpu","cpes":["cpe:2.3:h:mitsubishi:melsec_q04udvcpu:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26061","versionType":"custom"}]},{"vendor":"mitsubishi","product":"melsec_q06udvcpu","cpes":["cpe:2.3:h:mitsubishi:melsec_q06udvcpu:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26061","versionType":"custom"}]},{"vendor":"mitsubishi","product":"melsec_q13udvcpu","cpes":["cpe:2.3:h:mitsubishi:melsec_q13udvcpu:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26061","versionType":"custom"}]},{"vendor":"mitsubishi","product":"melsec_q26udvcpu","cpes":["cpe:2.3:h:mitsubishi:melsec_q26udvcpu:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26061","versionType":"custom"}]},{"vendor":"mitsubishi","product":"melsec_q06udpvcpu","cpes":["cpe:2.3:h:mitsubishi:melsec_q06udpvcpu:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26061","versionType":"custom"}]},{"vendor":"mitsubishi","product":"melsec_q13udpvcpu","cpes":["cpe:2.3:h:mitsubishi:melsec_q13udpvcpu:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26061","versionType":"custom"}]},{"vendor":"mitsubishi","product":"melsec_q26udpvcpu","cpes":["cpe:2.3:h:mitsubishi:melsec_q26udpvcpu:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26061","versionType":"custom"}]},{"vendor":"mitsubishielectric","product":"l02cpu-p","cpes":["cpe:2.3:h:mitsubishielectric:l02cpu-p:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26041","versionType":"custom"}]},{"vendor":"mitsubishi","product":"melsec_l06cpu\\(-p\\)","cpes":["cpe:2.3:h:mitsubishi:melsec_l06cpu\\(-p\\):-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26041","versionType":"custom"}]},{"vendor":"mitsubishi","product":"melsec_l26cpu\\(-p\\)","cpes":["cpe:2.3:h:mitsubishi:melsec_l26cpu\\(-p\\):-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26041","versionType":"custom"}]},{"vendor":"mitsubishielectric","product":"melsec_l02cpu-p","cpes":["cpe:2.3:h:mitsubishielectric:melsec_l02cpu-p:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26041","versionType":"custom"}]},{"vendor":"mitsubishielectric","product":"melsec_l06cpu-p","cpes":["cpe:2.3:h:mitsubishielectric:melsec_l06cpu-p:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26041","versionType":"custom"}]},{"vendor":"mitsubishielectric","product":"melsec_l26cpu-p","cpes":["cpe:2.3:h:mitsubishielectric:melsec_l26cpu-p:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26041","versionType":"custom"}]},{"vendor":"mitsubishielectric","product":"l26cpu-bt","cpes":["cpe:2.3:h:mitsubishielectric:l26cpu-bt:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26041","versionType":"custom"}]},{"vendor":"mitsubishielectric","product":"melsec_l26cpu-pbt","cpes":["cpe:2.3:h:mitsubishielectric:melsec_l26cpu-pbt:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"xxxxx26041","versionType":"custom"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-07-16T00:29:47.319671Z","id":"CVE-2024-0802","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-07-16T01:00:21.794Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-01T18:18:18.584Z"},"title":"CVE Program Container","references":[{"tags":["vendor-advisory","x_transferred"],"url":"https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-024_en.pdf"},{"tags":["government-resource","x_transferred"],"url":"https://jvn.jp/vu/JVNVU99690199/"},{"tags":["government-resource","x_transferred"],"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-24-074-14"}]}]}}