Denial of service in Mitsubishi Electric MELSEC-Q Series PLCs



Published: 2019-01-30
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2019-6535
CWE-ID CWE-400
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
Q100UDEHCPU
Hardware solutions / Firmware

Q50UDEHCPU
Hardware solutions / Firmware

Q26UDEHCPU
Hardware solutions / Firmware

Q20UDEHCPU
Hardware solutions / Firmware

Q13UDEHCPU
Hardware solutions / Firmware

Q10UDEHCPU
Hardware solutions / Firmware

Q06UDEHCPU
Hardware solutions / Firmware

Q04UDEHCPU
Hardware solutions / Firmware

Q26UDPVCPU
Hardware solutions / Firmware

Q13UDPVCPU
Hardware solutions / Firmware

Q06UDPVCPU
Hardware solutions / Firmware

Q04UDPVCPU
Hardware solutions / Firmware

Q26UDVCPU
Hardware solutions / Firmware

Q13UDVCPU
Hardware solutions / Firmware

Q06UDVCPU
Hardware solutions / Firmware

Q04UDVCPU
Hardware solutions / Firmware

Q03UDVCPU
Hardware solutions / Firmware

Vendor Mitsubishi Electric

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Resource exhaustion

EUVDB-ID: #VU17277

Risk: Low

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-6535

CWE-ID: CWE-400 - Resource exhaustion

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to resource exhaustion when handling malicious input. A remote attacker can send specific bytes over Port 5007, consume excessive resources and cause Ethernet stack crash.

Mitigation

Update the affected to the latest versions.

Vulnerable software versions

Q100UDEHCPU: All versions

Q50UDEHCPU: All versions

Q26UDEHCPU: All versions

Q20UDEHCPU: All versions

Q13UDEHCPU: All versions

Q10UDEHCPU: All versions

Q06UDEHCPU: All versions

Q04UDEHCPU: All versions

Q26UDPVCPU: All versions

Q13UDPVCPU: All versions

Q06UDPVCPU: All versions

Q04UDPVCPU: All versions

Q26UDVCPU: All versions

Q13UDVCPU: All versions

Q06UDVCPU: All versions

Q04UDVCPU: All versions

Q03UDVCPU: All versions

External links

http://ics-cert.us-cert.gov/advisories/ICSA-19-029-02


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###