CVE-2024-0802: Mitsubishi Melsec l06cpu\-P\
Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.
Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to read arbitrary information from a target product or execute malicious code on a target product by sending a specially crafted packet.
Affected products
- Mitsubishi Melsec l06cpu\-P\
- Mitsubishi Melsec l26cpu\-P\
- Mitsubishi Melsec q03udvcpu
- Mitsubishi Melsec q04udvcpu
- Mitsubishi Melsec q06udpvcpu
- Mitsubishi Melsec q06udvcpu
- Mitsubishi Melsec q13udpvcpu
- Mitsubishi Melsec q13udvcpu
- Mitsubishi Melsec q26udpvcpu
- Mitsubishi Melsec q26udvcpu
- Mitsubishi Electric Corporation Melsec-L Series l02cpu
- Mitsubishi Electric Corporation Melsec-L Series l02cpu-P
- Mitsubishi Electric Corporation Melsec-L Series l06cpu
- Mitsubishi Electric Corporation Melsec-L Series l06cpu-P
- Mitsubishi Electric Corporation Melsec-L Series l26cpu
- Mitsubishi Electric Corporation Melsec-L Series l26cpu-Bt
- Mitsubishi Electric Corporation Melsec-L Series l26cpu-P
- Mitsubishi Electric Corporation Melsec-L Series l26cpu-Pbt
- Mitsubishi Electric Corporation Melsec-Q Series q03udecpu
- Mitsubishi Electric Corporation Melsec-Q Series q03udvcpu
- Mitsubishi Electric Corporation Melsec-Q Series q04udehcpu
- Mitsubishi Electric Corporation Melsec-Q Series q04udpvcpu
- Mitsubishi Electric Corporation Melsec-Q Series q04udvcpu
- Mitsubishi Electric Corporation Melsec-Q Series q06udehcpu
- Mitsubishi Electric Corporation Melsec-Q Series q06udpvcpu
- and 26 more
Published 2024-03-15. Last modified 2026-06-17.