CISA issued multiple ICS advisories covering Mitsubishi Electric MELSEC controllers used in critical manufacturing, warning that several product lines are exposed to remotely exploitable flaws. The most severe issues affect MELSEC-Q/L Series factory automation controllers, where five vulnerabilities—CVE-2024-0802, CVE-2024-0803, CVE-2024-1915, CVE-2024-1916, and CVE-2024-1917—carry CVSS 9.8 ratings and could let an attacker read arbitrary information or execute malicious code by sending crafted packets. Mitsubishi released remediated versions tied to newer serial-number ranges, and CISA said no public exploitation had been reported at publication.
Separate advisories also warned that MELSEC iQ-R Series Safety CPU and SIL2 Process CPU modules contain flaws that can expose usernames through brute-force attempts (CVE-2021-20594), leak credentials via network sniffing (CVE-2021-20597), and lock out legitimate users after repeated failed logins (CVE-2021-20598). In addition, MELSEC iQ-R, Q, and L Series CPU modules are affected by an uncontrolled resource consumption bug, CVE-2020-5652, that can trigger a denial of service on the Ethernet port until the device is reset. Mitsubishi has provided firmware fixes for many affected systems, while CISA urged operators to isolate control networks, use firewalls or VPNs, block untrusted access, and apply compensating controls for legacy devices that cannot be updated.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
CISA published advisory ICSA-20-303-01 covering CVE-2020-5652, a remotely exploitable denial-of-service vulnerability in numerous Mitsubishi Electric MELSEC iQ-R, Q, and L Series controller CPU modules. The flaw can be triggered by a specially crafted packet and requires a reset for recovery; CISA said no known public exploitation had been reported.
Mitsubishi Electric released fixed versions for many MELSEC iQ-R, Q, and L Series programmable controller CPU modules affected by CVE-2020-5652, an uncontrolled resource consumption vulnerability that can cause denial of service on the Ethernet port. For legacy models that cannot be updated, the vendor recommended compensating controls such as firewalls, VPNs, LAN-only deployment, and blocking untrusted network access.
CISA published advisory ICSA-24-074-14 on multiple critical vulnerabilities in Mitsubishi Electric MELSEC-Q/L Series controllers. The advisory said successful exploitation could let remote attackers read arbitrary information or execute malicious code, and noted no known public exploitation at publication time.
Mitsubishi Electric released remediated MELSEC-Q and MELSEC-L Series products identified by later serial-number ranges to address five critical vulnerabilities with CVSS 9.8 scores. The flaws affected numerous factory automation controller CPU models and were remotely exploitable with low attack complexity.
Anton Dorfman of Positive Technologies reported multiple critical vulnerabilities affecting Mitsubishi Electric MELSEC-Q/L Series controllers to the vendor. The issues, later assigned CVE-2024-0802, CVE-2024-0803, CVE-2024-1915, CVE-2024-1916, and CVE-2024-1917, could enable arbitrary information disclosure or remote code execution via crafted packets.
CISA published advisory ICSA-21-250-01 covering three remotely exploitable vulnerabilities in Mitsubishi Electric MELSEC iQ-R Series Safety CPU and SIL2 Process CPU modules used in critical manufacturing environments. CISA said there was no known public exploitation at the time and recommended mitigations including firewalls, VPNs, IP filtering, and password changes via USB where applicable.
Mitsubishi Electric released fixed firmware for MELSEC iQ-R Series Safety CPU and SIL2 Process CPU modules affected by CVE-2021-20594 and CVE-2021-20597. The vulnerabilities could expose usernames through brute-force attempts and credentials through network sniffing, while CVE-2021-20598 required mitigations rather than a listed firmware fix.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
us-cert.cisa.gov
Open sourcecisa.gov
Open sourceus-cert.cisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.