CVE Feed

    Dashboard / CVE / CVE-2022-40265

    CVE-2022-40265

    Improper Input Validation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series RJ71EN71 Firmware version "65" and prior and Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120ENCPU Network Part Firmware version "65" and prior allows a remote unauthenticated attacker to cause a Denial of Service condition by sending specially crafted packets. A system reset is required for recovery.

    Published:Nov 30, 2022
    Last Modified:Apr 24, 2025
    EPS:Nov 30, 2022
    EPSS Score:0.00198
    CVSS Score:8.6

    Affected Products

    Vendor
    Mitsubishielectric
    Product
    R04encpu
    Vendor
    Mitsubishielectric
    Product
    R04encpu Firmware
    Vendor
    Mitsubishielectric
    Product
    R08encpu
    Vendor
    Mitsubishielectric
    Product
    R08encpu Firmware
    Vendor
    Mitsubishielectric
    Product
    R120encpu
    Vendor
    Mitsubishielectric
    Product
    R120encpu Firmware
    Vendor
    Mitsubishielectric
    Product
    R16encpu
    Vendor
    Mitsubishielectric
    Product
    R16encpu Firmware
    Vendor
    Mitsubishielectric
    Product
    R32encpu
    Vendor
    Mitsubishielectric
    Product
    R32encpu Firmware
    Vendor
    Mitsubishielectric
    Product
    Rj71en71
    Vendor
    Mitsubishielectric
    Product
    Rj71en71 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High