CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 263

As cited

Copy frozen at (site build).

vulnerabilities

Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M

Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M versions 1.000A through 1.014Q contain four vulnerabilities in the bundled 7-Zip component, including heap-based buffer overflow, NULL pointer dereference, link following, and path traversal flaws. These issues could allow local attackers to cause denial-of-service conditions, tamper with data, or execute arbitrary code when a user decompresses a specially crafted archive file. Mitsubishi Electric has released fixed version 1.015R or later, and recommends network segmentation and access controls for users unable to update immediately.

Why it matters: Critical manufacturing environments using affected versions should prioritize patching to version 1.015R or later to prevent arbitrary code execution through archive decompression attacks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M

Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M versions 1.000A through 1.014Q contain four vulnerabilities in the bundled 7-Zip component, including heap-based buffer overflow, NULL pointer dereference, link following, and path traversal flaws. These issues could allow local attackers to cause denial-of-service conditions, tamper with data, or execute arbitrary code when a user decompresses a specially crafted archive file. Mitsubishi Electric has released fixed version 1.015R or later, and recommends network segmentation and access controls for users unable to update immediately.

Why it matters: Critical manufacturing environments using affected versions should prioritize patching to version 1.015R or later to prevent arbitrary code execution through archive decompression attacks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary