CVE-2016-8368: Mitsubishielectric QJ71E71-100 Firmware
High severity, CVSS 8.6. EPSS: 2.6% chance of exploitation in the next 30 days.
An issue was discovered in Mitsubishi Electric Automation MELSEC-Q series Ethernet interface modules QJ71E71-100, all versions, QJ71E71-B5, all versions, and QJ71E71-B2, all versions. The affected Ethernet interface module is connected to a MELSEC-Q PLC, which may allow a remote attacker to connect to the PLC via Port 5002/TCP and cause a denial of service, requiring the PLC to be reset to resume operation. This is caused by an Unrestricted Externally Accessible Lock.
Affected products
- Mitsubishielectric QJ71E71-100 Firmware: affected versions not specified
- Mitsubishielectric QJ71E71-b2 Firmware: affected versions not specified
- Mitsubishielectric QJ71E71-b5 Firmware: affected versions not specified
Published 2017-02-13. Last modified 2026-06-17.