CVE Feed

    Dashboard / CVE / CVE-2016-8368

    CVE-2016-8368

    An issue was discovered in Mitsubishi Electric Automation MELSEC-Q series Ethernet interface modules QJ71E71-100, all versions, QJ71E71-B5, all versions, and QJ71E71-B2, all versions. The affected Ethernet interface module is connected to a MELSEC-Q PLC, which may allow a remote attacker to connect to the PLC via Port 5002/TCP and cause a denial of service, requiring the PLC to be reset to resume operation. This is caused by an Unrestricted Externally Accessible Lock.

    Published:Feb 13, 2017
    Last Modified:Apr 20, 2025
    EPS:Feb 13, 2017
    EPSS Score:0.00686
    CVSS Score:8.6

    Affected Products

    Vendor
    Mitsubishielectric
    Product
    Qj71e71-100
    Vendor
    Mitsubishielectric
    Product
    Qj71e71-100 Firmware
    Vendor
    Mitsubishielectric
    Product
    Qj71e71-b2
    Vendor
    Mitsubishielectric
    Product
    Qj71e71-b2 Firmware
    Vendor
    Mitsubishielectric
    Product
    Qj71e71-b5
    Vendor
    Mitsubishielectric
    Product
    Qj71e71-b5 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High