Input validation error in Mitsubishi Electric products - CVE-2024-7316

 

Input validation error in Mitsubishi Electric products - CVE-2024-7316

Published: October 22, 2024


Vulnerability identifier: #VU99233
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-7316
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in Numerical Control Systems (CNC). A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

M750VW
NC Trainer2 plus
NC Trainer2
E70
M70V
M720VS
M730VS
M750VS
M720VW
M730VW
M800VW
C80
E80
M80W
M80
M800S
M800W
M80VW
M80V
M800VS

How to mitigate CVE-2024-7316

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins