#VU99233 Input validation error in Mitsubishi Electric products - CVE-2024-7316
Published: October 22, 2024
Vulnerability identifier: #VU99233
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2024-7316
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
M800VW
M800VS
M80V
M80VW
M800W
M800S
M80
M80W
E80
C80
M750VW
M730VW
M720VW
M750VS
M730VS
M720VS
M70V
E70
NC Trainer2
NC Trainer2 plus
M800VW
M800VS
M80V
M80VW
M800W
M800S
M80
M80W
E80
C80
M750VW
M730VW
M720VW
M750VS
M730VS
M720VS
M70V
E70
NC Trainer2
NC Trainer2 plus
Software vendor:
Mitsubishi Electric
Mitsubishi Electric
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in Numerical Control Systems (CNC). A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.