#VU99233 Input validation error in Mitsubishi Electric products - CVE-2024-7316

 

#VU99233 Input validation error in Mitsubishi Electric products - CVE-2024-7316

Published: October 22, 2024


Vulnerability identifier: #VU99233
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2024-7316
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
M800VW
M800VS
M80V
M80VW
M800W
M800S
M80
M80W
E80
C80
M750VW
M730VW
M720VW
M750VS
M730VS
M720VS
M70V
E70
NC Trainer2
NC Trainer2 plus
Software vendor:
Mitsubishi Electric

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in Numerical Control Systems (CNC). A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links