CVE Feed

    Dashboard / CVE / CVE-2022-25159

    CVE-2022-25159

    Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R series R00/01/02CPU all versions, Mitsubishi Electric MELSEC iQ-R series R04/08/16/32/120(EN)CPU all versions, Mitsubishi Electric MELSEC iQ-R series R08/16/32/120SFCPU all versions, Mitsubishi Electric MELSEC iQ-R series R08/16/32/120PCPU all versions, Mitsubishi Electric MELSEC iQ-R series R08/16/32/120PSFCPU all versions, Mitsubishi Electric MELSEC iQ-R series R16/32/64MTCPU all versions, Mitsubishi Electric MELSEC iQ-R series RJ71C24(-R2/R4) all versions, Mitsubishi Electric MELSEC iQ-R series RJ71EN71 all versions, Mitsubishi Electric MELSEC iQ-R series RJ72GF15-T2 all versions, Mitsubishi Electric MELSEC Q series Q03/04/06/13/26UDVCPU all versions, Mitsubishi Electric MELSEC Q series Q04/06/13/26UDPVCPU all versions, Mitsubishi Electric MELSEC Q series QJ71C24N(-R2/R4) all versions and Mitsubishi Electric MELSEC Q series QJ71E71-100 all versions allows a remote unauthenticated attacker to login to the product by replay attack.

    Published:Apr 1, 2022
    Last Modified:Nov 21, 2024
    EPS:Apr 1, 2022
    EPSS Score:0.00627
    CVSS Score:8.1

    Affected Products

    Vendor
    Mitsubishielectric
    Product
    Fx5uc
    Vendor
    Mitsubishielectric
    Product
    Fx5uc-32mr\/ds-ts
    Vendor
    Mitsubishielectric
    Product
    Fx5uc-32mr\/ds-ts Firmware
    Vendor
    Mitsubishielectric
    Product
    Fx5uc-32mt\/d
    Vendor
    Mitsubishielectric
    Product
    Fx5uc-32mt\/d Firmware
    Vendor
    Mitsubishielectric
    Product
    Fx5uc-32mt\/ds-ts
    Vendor
    Mitsubishielectric
    Product
    Fx5uc-32mt\/ds-ts Firmware
    Vendor
    Mitsubishielectric
    Product
    Fx5uc-32mt\/dss
    Vendor
    Mitsubishielectric
    Product
    Fx5uc-32mt\/dss-ts
    Vendor
    Mitsubishielectric
    Product
    Fx5uc-32mt\/dss-ts Firmware
    Vendor
    Mitsubishielectric
    Product
    Fx5uc-32mt\/dss Firmware
    Vendor
    Mitsubishielectric
    Product
    Fx5uc Firmware
    Vendor
    Mitsubishielectric
    Product
    Fx5uj
    Vendor
    Mitsubishielectric
    Product
    Fx5uj-24mr\/es
    Vendor
    Mitsubishielectric
    Product
    Fx5uj-24mr\/es Firmware
    Vendor
    Mitsubishielectric
    Product
    Fx5uj-24mt\/es
    Vendor
    Mitsubishielectric
    Product
    Fx5uj-24mt\/es Firmware
    Vendor
    Mitsubishielectric
    Product
    Fx5uj-24mt\/ess
    Vendor
    Mitsubishielectric
    Product
    Fx5uj-24mt\/ess Firmware
    Vendor
    Mitsubishielectric
    Product
    Fx5uj-40mr\/es
    Vendor
    Mitsubishielectric
    Product
    Fx5uj-40mr\/es Firmware
    Vendor
    Mitsubishielectric
    Product
    Fx5uj-40mt\/es
    Vendor
    Mitsubishielectric
    Product
    Fx5uj-40mt\/es Firmware
    Vendor
    Mitsubishielectric
    Product
    Fx5uj-40mt\/ess
    Vendor
    Mitsubishielectric
    Product
    Fx5uj-40mt\/ess Firmware
    Vendor
    Mitsubishielectric
    Product
    Fx5uj-60mr\/es
    Vendor
    Mitsubishielectric
    Product
    Fx5uj-60mr\/es Firmware
    Vendor
    Mitsubishielectric
    Product
    Fx5uj-60mt\/es
    Vendor
    Mitsubishielectric
    Product
    Fx5uj-60mt\/es Firmware
    Vendor
    Mitsubishielectric
    Product
    Fx5uj-60mt\/ess
    Vendor
    Mitsubishielectric
    Product
    Fx5uj-60mt\/ess Firmware
    Vendor
    Mitsubishielectric
    Product
    Fx5uj Firmware

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High