GHSA-xwg7-jq5f-xfcj · Severity: high — Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC-Q Series Q03UDECPU all...
Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V firmware versions "16" and prior, Mitsubishi Electric MELSEC-Q Series Q03UDECPU the first 5 digits of serial No. "24061" and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/10/13/20/26/50/100UDEHCPU the first 5 digits of serial No. "24061" and prior, Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/13/26UDPVCPU the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-Q Series Q12DCCPU-V all versions, Mitsubishi Electric MELSEC-Q Series Q24DHCCPU-V(G) all versions, Mitsubishi Electric MELSEC-Q Series Q24/26DHCCPU-LS all versions, Mitsubishi Electric MELSEC-L series L02/06/26CPU(-P) the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-L series L26CPU-(P)BT the first 5 digits of serial number "24051" and prior and Mitsubishi Electric MELIPC Series MI5122-VW firmware versions "05" and prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition in Ethernet communications by sending specially crafted packets. A system reset of the products is required for recovery.
Conclusion & alert: CVE-2022-24946 is rated Moderate Risk (56.2/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.54%). Core evidence: EPSS rose +1.10% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.44% | 1.54% | +1.10% |
| 2 | 2025-11-21 | 0.61% | 0.44% | -0.17% |
| 3 | 2025-11-18 | — | 0.61% | — |
Full EPSS history (17 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| 7.8 | 2.0 | HIGH |
|
10.0 | 6.9 | [email protected] |
GHSA-xwg7-jq5f-xfcj · Severity: high — Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC-Q Series Q03UDECPU all...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| mitsubishielectric | q03udecpu_firmware | — | cpe:2.3:o:mitsubishielectric:q03udecpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | q04udehcpu_firmware | — | cpe:2.3:o:mitsubishielectric:q04udehcpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | q04udpvcpu_firmware | — | cpe:2.3:o:mitsubishielectric:q04udpvcpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | q04udvcpu_firmware | — | cpe:2.3:o:mitsubishielectric:q04udvcpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | q100udehcpu_firmware | — | cpe:2.3:o:mitsubishielectric:q100udehcpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | q50udehcpu_firmware | — | cpe:2.3:o:mitsubishielectric:q50udehcpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | q26dhccpu-ls_firmware | — | cpe:2.3:o:mitsubishielectric:q26dhccpu-ls_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | q26udehcpu_firmware | — | cpe:2.3:o:mitsubishielectric:q26udehcpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | q26udpvcpu_firmware | — | cpe:2.3:o:mitsubishielectric:q26udpvcpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | q26udvcpu_firmware | — | cpe:2.3:o:mitsubishielectric:q26udvcpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | q20udehcpu_firmware | — | cpe:2.3:o:mitsubishielectric:q20udehcpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | q13udehcpu_firmware | — | cpe:2.3:o:mitsubishielectric:q13udehcpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | q13udpvcpu_firmware | — | cpe:2.3:o:mitsubishielectric:q13udpvcpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | q13udvcpu_firmware | — | cpe:2.3:o:mitsubishielectric:q13udvcpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | q10udehcpu_firmware | — | cpe:2.3:o:mitsubishielectric:q10udehcpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | q06ccpu-v_firmware | — | cpe:2.3:o:mitsubishielectric:q06ccpu-v_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | q06phcpu_firmware | — | cpe:2.3:o:mitsubishielectric:q06phcpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | q06udehcpu_firmware | — | cpe:2.3:o:mitsubishielectric:q06udehcpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | q06udpvcpu_firmware | — | cpe:2.3:o:mitsubishielectric:q06udpvcpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | q06udvcpu_firmware | — | cpe:2.3:o:mitsubishielectric:q06udvcpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | l02cpu_firmware | — | cpe:2.3:o:mitsubishielectric:l02cpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | l02cpu-p_firmware | — | cpe:2.3:o:mitsubishielectric:l02cpu-p_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | l02scpu_firmware | — | cpe:2.3:o:mitsubishielectric:l02scpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | l02scpu-p_firmware | — | cpe:2.3:o:mitsubishielectric:l02scpu-p_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | l06cpu_firmware | — | cpe:2.3:o:mitsubishielectric:l06cpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | l06cpu-p_firmware | — | cpe:2.3:o:mitsubishielectric:l06cpu-p_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | l26cpu_firmware | — | cpe:2.3:o:mitsubishielectric:l26cpu_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | l26cpu-\(p\)bt_firmware | — | cpe:2.3:o:mitsubishielectric:l26cpu-\(p\)bt_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | l26cpu-bt_firmware | — | cpe:2.3:o:mitsubishielectric:l26cpu-bt_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | l26cpu-bt-cm_firmware | — | cpe:2.3:o:mitsubishielectric:l26cpu-bt-cm_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | l26cpu-p_firmware | — | cpe:2.3:o:mitsubishielectric:l26cpu-p_firmware:-:*:*:*:*:*:*:* |
| mitsubishielectric | l26cpu-pbt_firmware | — | cpe:2.3:o:mitsubishielectric:l26cpu-pbt_firmware:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://jvn.jp/vu/JVNVU90895626/index.html | Third Party Advisory |
| https://www.cisa.gov/uscert/ics/advisories/icsa-22-172-01 | |
| https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-007_en.pdf | Vendor Advisory |