{"id": "CVE-2023-3346", "cveTags": [], "metrics": {"cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}, {"type": "Secondary", "source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}]}, "published": "2023-08-03T05:15:10.603", "references": [{"url": "https://jvn.jp/vu/JVNVU90352157/index.html", "tags": ["Third Party Advisory"], "source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp"}, {"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-208-03", "tags": ["Third Party Advisory", "US Government Resource"], "source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp"}, {"url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-007_en.pdf", "tags": ["Vendor Advisory"], "source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-120"}]}, {"type": "Secondary", "source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp", "description": [{"lang": "en", "value": "CWE-120"}]}], "descriptions": [{"lang": "en", "value": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition and execute arbitrary code on the product by sending specially crafted packets. In addition, system reset is required for recovery."}], "lastModified": "2023-08-11T21:01:53.977", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mitsubishielectric:c80_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4A2C7CEB-5419-4882-BECA-AB02BE7495ED"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mitsubishielectric:c80:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0DB46E5E-A87C-4604-8478-2E380DE15B31"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mitsubishielectric:e70_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "82CC77B6-113E-4E69-86C3-BDB958E0526C"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mitsubishielectric:e70:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "861626CF-6AC2-4BDE-9204-4F2DF49DA3DD"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mitsubishielectric:e80_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "58B7693B-002F-4D6B-81F4-0D220388EBFD"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mitsubishielectric:e80:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6DF27249-85E2-4F4D-9BD4-0C46799C5F57"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mitsubishielectric:m70v_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7FE99E00-C9B9-430D-B75A-040CFD4554BB"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mitsubishielectric:m70v:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5AD8A2A3-6F05-44D2-B8F2-AF55EFE20B42"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mitsubishielectric:m720vs_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "39A07397-727A-4B97-8F43-5CFE327E3865"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mitsubishielectric:m720vs:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F72BE81B-4619-4199-8C21-D86687BCAE84"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mitsubishielectric:m720vs_15-type_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B2E54EAC-DEA5-4A02-942A-46C7B4572806"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mitsubishielectric:m720vs_15-type:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "53FC9159-9F15-475E-B6C5-573AFFBBA2FF"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mitsubishielectric:m720vw_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "30C5B6DC-59BD-4776-8C85-8880C2F7E4F8"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mitsubishielectric:m720vw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7112B6B5-8BE6-4E9C-B6D6-F64A31A80E6B"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mitsubishielectric:m730vs_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "51074DCA-06DB-4826-9800-7CB2C0C3F278"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mitsubishielectric:m730vs:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2AFFF519-B76C-465C-9477-6D78787E9F1A"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mitsubishielectric:m730vs_15-type_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0C56F2A9-D660-41A9-B981-049254E48714"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mitsubishielectric:m730vs_15-type:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C146ACAB-EF80-429F-8766-B569DC26340E"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mitsubishielectric:m730vw_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6246A9B0-3FA3-485A-A496-C507B1843FE2"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mitsubishielectric:m730vw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "10B71551-4B72-4AD5-B84B-4CED5EC2D83E"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mitsubishielectric:m750vs_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3D9B05DD-6999-4791-A80B-201760E0211B"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mitsubishielectric:m750vs:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5E8E44BF-BF71-433C-B7FB-DE2634004D3E"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mitsubishielectric:m750vs_15-type_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BD5D709A-3D6E-49C3-93B5-3832730AEF7B"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mitsubishielectric:m750vs_15-type:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "60BEB709-AF9D-4219-B172-A587759B3342"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mitsubishielectric:m750vw_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1C3FC16E-D7DA-494B-81A1-4592C17CA7E9"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mitsubishielectric:m750vw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "753EB189-5262-443D-8755-BEAF00E92D73"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mitsubishielectric:m80_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B563724A-AA22-45E5-956B-D8BA51103019"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mitsubishielectric:m80:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5EC6F60E-A347-4548-ABE4-79810909A35C"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mitsubishielectric:m800s_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "52768FEC-7702-46DB-BDAB-BA0F755BE63E"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mitsubishielectric:m800s:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8A1D9E22-4B8C-4410-B048-A4F788041859"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mitsubishielectric:m800vs_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "25030420-528F-45F4-A8D6-0D5A26B4C76C"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mitsubishielectric:m800vs:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "EB41007C-BD6F-4021-AD65-5DDBA614651E"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mitsubishielectric:m800vw_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "97EEFDE5-AEF0-4AB6-993A-D9F38A8CEEFD"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mitsubishielectric:m800vw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7D4BB785-DCE3-4B75-9988-BB0F4DB5995B"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mitsubishielectric:m800w_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6A8D3F93-1889-40B8-940D-64FF5219F3D3"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mitsubishielectric:m800w:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D9AAE983-B324-47B3-A0CF-DCB99411CBFA"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mitsubishielectric:m80v_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "579711D7-A4E8-4313-B404-4D662A37FD63"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mitsubishielectric:m80v:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0E202965-D914-4A4C-BE8A-860EDA0ADFD5"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mitsubishielectric:m80vw_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A3F836BE-AF19-45AC-BE38-B75634733EF1"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mitsubishielectric:m80vw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C845690F-D539-477B-987A-EC7EEEFB4C66"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mitsubishielectric:m80w_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "81C5D5C5-D0A7-4629-9238-E5BF62BB84C3"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mitsubishielectric:m80w:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "269F1D28-50E1-41A3-BBCF-E71EB68D3FEF"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp"}