Published:2020/02/17  Last Updated:2020/02/17

JVNVU#95424547
Multiple vulnerabilities in TCP/IP function on Mitsubishi Electric MELSEC C Controller Module and MELIPC Series MI5000

Overview

MELSEC C Controller Module and MELIPC Series MI5000 provided by Mitsubishi Electric Corporation have multiple vulnerabilities due to the TCP/IP function (IPnet) of VxWorks, a real-time OS distributed by Wind River.

Products Affected

The following products and serial numbers among MELSEC-Q series, MESEC iQ-R series C Controller Module, and MELIPC series MI5000 are affected.

[MELSEC-Q Series C Controller Module]

  • Q24DHCCPU-V, Q24DHCCPU-VG User Ethernet port (CH1, CH2): First 5 digits of serial number are 21121 or before
[MELSEC iQ-R Series C Controller Module / C Intelligent Function Module]
  • R12CCPU-V Ethernet port (CH1, CH2): First 2 digits of serial number are 11 or before
  • RD55UP06-V Ethernet port: First 2 digits of serial number are 08 or before
[MELIPC Series MI5000]
  • MI5122-VW Ethernet port (CH1): First 2 digits of serial number are 03 or before, or the firmware version is 03 or before
For the details, refer to the information provided by the developer.

Description

MELSEC C Controller Module and MELIPC Series MI5000 provided by Mitsubishi Electric Corporation have multiple vulnerabilities due to the vulnerabilities called "URGENT/11" in TCP/IP function (IPnet) of VxWorks, a real-time OS distributed by Wind River.

For the details, refer to the information provided by the developer.

Impact

Receiving a TCP packet crafted by a remote attacker may cause a denial of service (DoS) condition or malware being executed.

Solution

Update the Firmware
Apply the appropriate firmware update according to the information provided by the developer.

[MELSEC-Q Series C Controller Module]

  • Q24DHCCPU-V, Q24DHCCPU-VG: First 5 digits of serial number are "21122" or later
[MELSEC iQ-R Series C Controller Module / C Intelligent Function Module]
  • R12CCPU-V: First 2 digits of serial number are "12" or later
  • RD55UP06-V: First 2 digits of serial number are "09" or later
[MELIPC Series MI5000]
  • MI5122-VW: First 2 digits of serial number are "04" or later, or the firmware version is "04" or later
Apply the Workaround
Applying the following workaround may mitigate the impacts of the vulnerabilities.
  • Restrict access to the network
For the details, refer to the information provided by the developer.

References

  1. ICS Advisory (ICSA-19-274-01)
    Interpeak IPnet TCP/IP Stack (Update B)
  2. Wind River Systems, Inc.
    SECURITY VULNERABILITY RESPONSE INFORMATION TCP/IP Network Stack (IPnet, Urgent/11)

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Mitsubishi Electric Corporation reported these vulnerabilities to JPCERT/CC to notify users of the solution through JVN.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2020-5531
JVN iPedia