CVE-2022-24946
Description
Improper resource locking vulnerability in multiple Mitsubishi Electric PLC and MELIPC series allows remote unauthenticated attackers to cause a denial-of-service condition via specially crafted packets.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Improper resource locking vulnerability in multiple Mitsubishi Electric PLC and MELIPC series allows remote unauthenticated attackers to cause a denial-of-service condition via specially crafted packets.
Vulnerability
An improper resource locking vulnerability exists in the Ethernet communication handling of Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V (firmware version 16 and prior), MELSEC-Q Series (various models with specific serial number ranges), MELSEC-L Series (serial numbers 24051 and prior), and MELIPC Series MI5122-VW (firmware version 05 and prior) [1][2]. The flaw occurs when the device processes specially crafted packets, leading to a locked resource that prevents further Ethernet communication.
Exploitation
An attacker can exploit this vulnerability remotely without authentication by sending specially crafted packets to the Ethernet interface of the affected device [1][2]. No user interaction or special network position is required beyond network access to the device.
Impact
Successful exploitation causes a denial-of-service (DoS) condition affecting Ethernet communication on the target device [1][2]. Normal operation cannot resume without a system reset (power cycle or hardware reset) of the affected product [1].
Mitigation
Mitsubishi Electric has not released firmware updates for all affected product lines as of the publication date [2]. Users should refer to the vendor advisory [1] and CISA advisory [2] for the latest information. Recommended mitigations include restricting network access to the affected devices, implementing firewall rules, and contacting Mitsubishi Electric support for available firmware updates [2].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Mitsubishi Electric/MELSEC iQ-R Series R12CCPU-Vdescription
- Range: <=05
- Range: <=16
- Range: <24061
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
3- jvn.jp/vu/JVNVU90895626/index.htmlnvdThird Party Advisory
- www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-007_en.pdfnvdVendor Advisory
- www.cisa.gov/uscert/ics/advisories/icsa-22-172-01nvd
News mentions
0No linked articles in our index yet.