CISA issued multiple advisories covering vulnerabilities in Mitsubishi Electric industrial control system products, including MELFA SD/SQ and F-series robot controllers, MELSEC iQ-F, iQ-R, Q, L series, and MELIPC platforms. The most severe issues included remotely exploitable authentication weaknesses in factory automation devices and an authentication bypass in robot controllers caused by active debug code, tracked as CVE-2022-33323, which could permit unauthorized telnet access. Other flaws, including CVE-2022-25155 through CVE-2022-25160, involved weak or improper authentication handling, cleartext storage of sensitive information, and capture-replay abuse that could let unauthenticated attackers log in, disclose data, tamper with product information, or impersonate legitimate users.
A separate advisory also warned that multiple Intel third-party component vulnerabilities affected Mitsubishi Electric factory automation products, creating risks including privilege escalation, parameter disclosure, and denial of service, with a worst-case CVSS v3 8.8. Mitsubishi Electric released firmware updates or mitigation guidance and directed customers to vendor bulletins and Intel advisories where applicable. CISA urged operators to limit network exposure, isolate control systems from business networks, use firewalls or VPNs for remote access, restrict physical access where relevant, and follow standard ICS hardening practices. The advisories said no known public exploits were specifically targeting these vulnerabilities at the time of publication.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
CISA published Update D for a critical classic buffer overflow vulnerability, CVE-2023-1424, affecting multiple Mitsubishi Electric MELSEC iQ-F and iQ-R Series CPU modules. Mitsubishi Electric released fixed firmware for many models and provided mitigations for unsupported products; CISA said no known public exploitation had been reported.
CISA published an advisory covering multiple Intel third-party component vulnerabilities affecting Mitsubishi Electric MELIPC, MELSEC iQ-R, and MELSEC Q Series products. The issues could enable privilege escalation, disclosure of parameter information, or denial of service, and Mitsubishi Electric directed users to Intel advisories and its own bulletin for mitigations.
CISA published an advisory for CVE-2022-33323 affecting Mitsubishi Electric MELFA SD/SQ series and F-series robot controllers, where active debug code enabled unauthorized telnet login and remote authentication bypass. Mitsubishi Electric released updated firmware and advised customers to restrict network exposure and use firewalls or VPNs for remote access.
CISA published Update A for Mitsubishi Electric FA products, detailing multiple remotely exploitable authentication and sensitive information handling flaws affecting MELSEC iQ-F, iQ-R, Q, and L series devices. The vulnerabilities could allow unauthenticated attackers to log in, disclose sensitive information, tamper with data, or impersonate legitimate users; no known public exploits were reported.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.