CISA and Mitsubishi Electric disclosed multiple denial-of-service vulnerabilities affecting MELSEC iQ-R industrial controllers and related modules used in the critical manufacturing sector. The issues include improper input validation in CVE-2022-40265, improper session management in CVE-2021-20591, and uncontrolled resource consumption flaws tracked as CVE-2020-5666 and CVE-2020-5527. The vulnerabilities can be exploited remotely in various configurations to disrupt communications, block legitimate client connections, or force affected devices into an unresponsive state that may require a system reset or port recovery.
Affected products span MELSEC iQ-R CPU modules, Ethernet interfaces, C Controller modules, and broader MELSEC controller families including iQ-F, Q, L, and F series in some cases. Mitsubishi Electric issued firmware updates and mitigations such as disabling unnecessary web server functions, upgrading to fixed firmware, restricting network access with firewalls and IP filtering, and limiting exposure to trusted LAN environments or VPN-protected remote access. CISA also urged operators to isolate control systems from business networks and reduce Internet exposure; at the time of the advisories, no known public exploits were reported as specifically targeting these flaws.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
CISA published an advisory for CVE-2022-40265, an improper input validation vulnerability in Mitsubishi Electric MELSEC iQ-R Series products that could be exploited remotely without authentication to cause a denial-of-service condition requiring a system reset. Mitsubishi Electric released fixes in firmware version 66 or later and recommended network access restrictions and filtering.
CISA published Update B for its Mitsubishi Electric MELSEC iQ-R Series C Controller Module advisory. The provided reference does not include technical synopsis details, but it indicates a distinct advisory update event.
CISA issued an advisory for CVE-2021-20591, an uncontrolled resource consumption issue in Mitsubishi Electric MELSEC iQ-R Series CPU modules caused by improper session management. The flaw could prevent legitimate clients from connecting, and Mitsubishi Electric recommended network restrictions, IP filtering, and recovery steps.
Mitsubishi Electric disclosed CVE-2020-5666, an uncontrolled resource consumption vulnerability in MELSEC iQ-R series CPU modules that could be exploited remotely to cause a denial-of-service condition when the CPU module web server is enabled. Fixed firmware versions were released, and researcher Xiaofei.Zhang was credited with reporting the issue.
CISA published an advisory for CVE-2020-5527, an uncontrolled resource consumption vulnerability affecting Mitsubishi Electric MELSEC programmable controllers using the MELSOFT transmission port over UDP/IP. The issue could be exploited remotely to disrupt communications or make devices unresponsive across MELSEC iQ-R, iQ-F, Q, L, and F series products.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourceus-cert.cisa.gov
Open sourceus-cert.cisa.gov
Open sourceus-cert.cisa.gov
Open sourceus-cert.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.