CVE-2022-25161
📋 TL;DR
This vulnerability allows remote unauthenticated attackers to cause a denial-of-service condition in affected Mitsubishi Electric MELSEC iQ-F series PLCs by sending specially crafted packets. The attack disrupts program execution or communication, requiring a system reset for recovery. Organizations using these specific PLC models with vulnerable firmware versions are affected.
💻 Affected Systems
- Mitsubishi Electric MELSEC iQ-F series FX5U
- Mitsubishi Electric MELSEC iQ-F series FX5UC
- Mitsubishi Electric MELSEC iQ-F series FX5UJ
- Mitsubishi Electric MELSEC iQ-F series FX5S
📦 What is this software?
Melsec Iq Fx5s 30mr\/es Firmware by Mitsubishielectric
Melsec Iq Fx5s 30mr\/ess Firmware by Mitsubishielectric
Melsec Iq Fx5s 30mt\/es Firmware by Mitsubishielectric
Melsec Iq Fx5s 30mt\/ess Firmware by Mitsubishielectric
Melsec Iq Fx5s 40mr\/es Firmware by Mitsubishielectric
Melsec Iq Fx5s 40mr\/ess Firmware by Mitsubishielectric
Melsec Iq Fx5s 40mt\/es Firmware by Mitsubishielectric
Melsec Iq Fx5s 40mt\/ess Firmware by Mitsubishielectric
Melsec Iq Fx5s 60mr\/es Firmware by Mitsubishielectric
Melsec Iq Fx5s 60mr\/ess Firmware by Mitsubishielectric
Melsec Iq Fx5s 60mt\/es Firmware by Mitsubishielectric
Melsec Iq Fx5s 60mt\/ess Firmware by Mitsubishielectric
Melsec Iq Fx5s 80mr\/es Firmware by Mitsubishielectric
Melsec Iq Fx5s 80mr\/ess Firmware by Mitsubishielectric
Melsec Iq Fx5s 80mt\/es Firmware by Mitsubishielectric
Melsec Iq Fx5s 80mt\/ess Firmware by Mitsubishielectric
Melsec Iq Fx5u 32mr\/ds Firmware by Mitsubishielectric
Melsec Iq Fx5u 32mr\/ds Firmware by Mitsubhishielectric
Melsec Iq Fx5u 32mr\/dss Firmware by Mitsubishielectric
Melsec Iq Fx5u 32mr\/dss Firmware by Mitsubhishielectric
Melsec Iq Fx5u 32mr\/es Firmware by Mitsubishielectric
Melsec Iq Fx5u 32mr\/es Firmware by Mitsubhishielectric
Melsec Iq Fx5u 32mr\/ess Firmware by Mitsubishielectric
Melsec Iq Fx5u 32mr\/ess Firmware by Mitsubhishielectric
Melsec Iq Fx5u 32mt\/ds Firmware by Mitsubishielectric
Melsec Iq Fx5u 32mt\/ds Firmware by Mitsubhishielectric
Melsec Iq Fx5u 32mt\/dss Firmware by Mitsubishielectric
Melsec Iq Fx5u 32mt\/dss Firmware by Mitsubhishielectric
Melsec Iq Fx5u 32mt\/es Firmware by Mitsubishielectric
Melsec Iq Fx5u 32mt\/es Firmware by Mitsubhishielectric
Melsec Iq Fx5u 32mt\/ess Firmware by Mitsubishielectric
Melsec Iq Fx5u 32mt\/ess Firmware by Mitsubhishielectric
Melsec Iq Fx5u 64mr\/ds Firmware by Mitsubishielectric
Melsec Iq Fx5u 64mr\/ds Firmware by Mitsubhishielectric
Melsec Iq Fx5u 64mr\/dss Firmware by Mitsubishielectric
Melsec Iq Fx5u 64mr\/dss Firmware by Mitsubhishielectric
Melsec Iq Fx5u 64mr\/es Firmware by Mitsubishielectric
Melsec Iq Fx5u 64mr\/es Firmware by Mitsubhishielectric
Melsec Iq Fx5u 64mr\/ess Firmware by Mitsubishielectric
Melsec Iq Fx5u 64mr\/ess Firmware by Mitsubhishielectric
Melsec Iq Fx5u 64mt\/ds Firmware by Mitsubishielectric
Melsec Iq Fx5u 64mt\/ds Firmware by Mitsubhishielectric
Melsec Iq Fx5u 64mt\/dss Firmware by Mitsubishielectric
Melsec Iq Fx5u 64mt\/dss Firmware by Mitsubhishielectric
Melsec Iq Fx5u 64mt\/es Firmware by Mitsubishielectric
Melsec Iq Fx5u 64mt\/es Firmware by Mitsubhishielectric
Melsec Iq Fx5u 64mt\/ess Firmware by Mitsubishielectric
Melsec Iq Fx5u 64mt\/ess Firmware by Mitsubhishielectric
Melsec Iq Fx5u 80mr\/ds Firmware by Mitsubishielectric
Melsec Iq Fx5u 80mr\/ds Firmware by Mitsubhishielectric
Melsec Iq Fx5u 80mr\/dss Firmware by Mitsubishielectric
Melsec Iq Fx5u 80mr\/dss Firmware by Mitsubhishielectric
Melsec Iq Fx5u 80mr\/es Firmware by Mitsubishielectric
Melsec Iq Fx5u 80mr\/es Firmware by Mitsubhishielectric
Melsec Iq Fx5u 80mr\/ess Firmware by Mitsubishielectric
Melsec Iq Fx5u 80mr\/ess Firmware by Mitsubhishielectric
Melsec Iq Fx5u 80mt\/ds Firmware by Mitsubishielectric
Melsec Iq Fx5u 80mt\/ds Firmware by Mitsubhishielectric
Melsec Iq Fx5u 80mt\/dss Firmware by Mitsubishielectric
Melsec Iq Fx5u 80mt\/dss Firmware by Mitsubhishielectric
Melsec Iq Fx5u 80mt\/es Firmware by Mitsubishielectric
Melsec Iq Fx5u 80mt\/es Firmware by Mitsubhishielectric
Melsec Iq Fx5u 80mt\/ess Firmware by Mitsubishielectric
Melsec Iq Fx5u 80mt\/ess Firmware by Mitsubhishielectric
Melsec Iq Fx5uc 32mr\/dds Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uc 32mr\/dds Firmware →
Melsec Iq Fx5uc 32mr\/dds Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uc 32mr\/dds Firmware →
Melsec Iq Fx5uc 32mr\/ds Firmware by Mitsubishielectric
Melsec Iq Fx5uc 32mr\/ds Firmware by Mitsubishielectric
Melsec Iq Fx5uc 32mr\/ds Ts Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uc 32mr\/ds Ts Firmware →
Melsec Iq Fx5uc 32mt\/dds Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uc 32mt\/dds Firmware →
Melsec Iq Fx5uc 32mt\/dds Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uc 32mt\/dds Firmware →
Melsec Iq Fx5uc 32mt\/ds Firmware by Mitsubishielectric
Melsec Iq Fx5uc 32mt\/ds Firmware by Mitsubishielectric
Melsec Iq Fx5uc 32mt\/ds Ts Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uc 32mt\/ds Ts Firmware →
Melsec Iq Fx5uc 32mt\/dss Ts Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uc 32mt\/dss Ts Firmware →
Melsec Iq Fx5uc 64mr\/dds Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uc 64mr\/dds Firmware →
Melsec Iq Fx5uc 64mr\/dds Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uc 64mr\/dds Firmware →
Melsec Iq Fx5uc 64mr\/ds Firmware by Mitsubishielectric
Melsec Iq Fx5uc 64mr\/ds Firmware by Mitsubishielectric
Melsec Iq Fx5uc 64mt\/dds Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uc 64mt\/dds Firmware →
Melsec Iq Fx5uc 64mt\/dds Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uc 64mt\/dds Firmware →
Melsec Iq Fx5uc 64mt\/ds Firmware by Mitsubishielectric
Melsec Iq Fx5uc 64mt\/ds Firmware by Mitsubishielectric
Melsec Iq Fx5uc 96mr\/dds Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uc 96mr\/dds Firmware →
Melsec Iq Fx5uc 96mr\/dds Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uc 96mr\/dds Firmware →
Melsec Iq Fx5uc 96mr\/ds Firmware by Mitsubishielectric
Melsec Iq Fx5uc 96mr\/ds Firmware by Mitsubishielectric
Melsec Iq Fx5uc 96mt\/dds Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uc 96mt\/dds Firmware →
Melsec Iq Fx5uc 96mt\/dds Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uc 96mt\/dds Firmware →
Melsec Iq Fx5uc 96mt\/ds Firmware by Mitsubishielectric
Melsec Iq Fx5uc 96mt\/ds Firmware by Mitsubishielectric
Melsec Iq Fx5uj 24mr\/es A Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uj 24mr\/es A Firmware →
Melsec Iq Fx5uj 24mr\/es Firmware by Mitsubishielectric
Melsec Iq Fx5uj 24mr\/ess Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uj 24mr\/ess Firmware →
Melsec Iq Fx5uj 24mt\/es A Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uj 24mt\/es A Firmware →
Melsec Iq Fx5uj 24mt\/es Firmware by Mitsubishielectric
Melsec Iq Fx5uj 24mt\/ess Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uj 24mt\/ess Firmware →
Melsec Iq Fx5uj 40mr\/es A Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uj 40mr\/es A Firmware →
Melsec Iq Fx5uj 40mr\/es Firmware by Mitsubishielectric
Melsec Iq Fx5uj 40mr\/ess Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uj 40mr\/ess Firmware →
Melsec Iq Fx5uj 40mt\/es A Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uj 40mt\/es A Firmware →
Melsec Iq Fx5uj 40mt\/es Firmware by Mitsubishielectric
Melsec Iq Fx5uj 40mt\/ess Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uj 40mt\/ess Firmware →
Melsec Iq Fx5uj 60mr\/es A Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uj 60mr\/es A Firmware →
Melsec Iq Fx5uj 60mr\/es Firmware by Mitsubishielectric
Melsec Iq Fx5uj 60mr\/ess Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uj 60mr\/ess Firmware →
Melsec Iq Fx5uj 60mt\/es A Firmware by Mitsubishielectric
View all CVEs affecting Melsec Iq Fx5uj 60mt\/es A Firmware →
Melsec Iq Fx5uj 60mt\/es Firmware by Mitsubishielectric
⚠️ Risk & Real-World Impact
Worst Case
Critical industrial processes are halted, requiring physical system reset and potentially causing production downtime, safety incidents, or equipment damage.
Likely Case
PLC stops executing control logic, halting industrial processes until manual reset is performed, causing operational disruption.
If Mitigated
With proper network segmentation and access controls, impact is limited to isolated control network segments.
🎯 Exploit Status
No public exploit code identified, but vulnerability details are public and exploitation appears straightforward.
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: FX5U/FX5UC: 1.270 or later (serial 17X****+) or 1.073 or later (serial 179****); FX5UJ: 1.030/1.031 or later; FX5S: no patch available (only version 1.000 exists)
Vendor Advisory: https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-004_en.pdf
Restart Required: Yes
Instructions:
1. Download firmware update from Mitsubishi Electric website. 2. Connect to PLC via programming software. 3. Backup current program. 4. Apply firmware update. 5. Restart PLC. 6. Restore program and verify operation.
🔧 Temporary Workarounds
Network segmentation
allIsolate PLCs in dedicated control network segments with firewall rules restricting access.
Access control lists
allImplement network ACLs to restrict which IP addresses can communicate with PLCs.
🧯 If You Can't Patch
- Implement strict network segmentation to isolate PLCs from untrusted networks
- Deploy intrusion detection systems monitoring for anomalous traffic to PLCs
🔍 How to Verify
Check if Vulnerable:
Check PLC model, serial number, and firmware version via Mitsubishi Electric programming software (GX Works3).
Check Version:
Use GX Works3 'Diagnostics' -> 'System Monitor' to view firmware version
Verify Fix Applied:
Confirm firmware version is patched via programming software and test communication resilience.
📡 Detection & Monitoring
Log Indicators:
- PLC error logs showing communication faults
- Unexpected PLC stop/reset events
Network Indicators:
- Unusual traffic patterns to PLC ports
- Malformed packets targeting PLC IP addresses
SIEM Query:
source_ip=* dest_ip=PLC_IP AND (packet_size_anomaly OR protocol_violation)
🔗 References
- https://jvn.jp/vu/JVNVU95926817/index.html
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-139-01
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-004_en.pdf
- https://jvn.jp/vu/JVNVU95926817/index.html
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-139-01
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-004_en.pdf