VYPR
High severity7.5NVD Advisory· Published Jun 15, 2022· Updated Jun 2, 2026

CVE-2022-24946

CVE-2022-24946

Description

Improper resource locking vulnerability in multiple Mitsubishi Electric PLC and MELIPC series allows remote unauthenticated attackers to cause a denial-of-service condition via specially crafted packets.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper resource locking vulnerability in multiple Mitsubishi Electric PLC and MELIPC series allows remote unauthenticated attackers to cause a denial-of-service condition via specially crafted packets.

Vulnerability

An improper resource locking vulnerability exists in the Ethernet communication handling of Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V (firmware version 16 and prior), MELSEC-Q Series (various models with specific serial number ranges), MELSEC-L Series (serial numbers 24051 and prior), and MELIPC Series MI5122-VW (firmware version 05 and prior) [1][2]. The flaw occurs when the device processes specially crafted packets, leading to a locked resource that prevents further Ethernet communication.

Exploitation

An attacker can exploit this vulnerability remotely without authentication by sending specially crafted packets to the Ethernet interface of the affected device [1][2]. No user interaction or special network position is required beyond network access to the device.

Impact

Successful exploitation causes a denial-of-service (DoS) condition affecting Ethernet communication on the target device [1][2]. Normal operation cannot resume without a system reset (power cycle or hardware reset) of the affected product [1].

Mitigation

Mitsubishi Electric has not released firmware updates for all affected product lines as of the publication date [2]. Users should refer to the vendor advisory [1] and CISA advisory [2] for the latest information. Recommended mitigations include restricting network access to the affected devices, implementing firewall rules, and contacting Mitsubishi Electric support for available firmware updates [2].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

3

News mentions

0

No linked articles in our index yet.