CVE-2023-1424: Mitsubishielectric Melsec Iq-FX5U-32mr/ds Firmware

High severity, CVSS 8.1. EPSS: 3.4% chance of exploitation in the next 30 days.

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules and MELSEC iQ-R Series CPU modules allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on a target product by sending specially crafted packets. A system reset of the product is required for recovery from a denial of service (DoS) condition and malicious code execution.

Affected products

Published 2023-05-24. Last modified 2026-06-17.