As cited
Copy frozen at (site build).
vulnerabilities
Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M
Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M versions 1.000A through 1.014Q contain four vulnerabilities in the bundled 7-Zip component, including heap-based buffer overflow, NULL pointer dereference, link following, and path traversal flaws. These issues could allow local attackers to cause denial-of-service conditions, tamper with data, or execute arbitrary code when a user decompresses a specially crafted archive file. Mitsubishi Electric has released fixed version 1.015R or later, and recommends network segmentation and access controls for users unable to update immediately.
Why it matters: Critical manufacturing environments using affected versions should prioritize patching to version 1.015R or later to prevent arbitrary code execution through archive decompression attacks.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M
Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M versions 1.000A through 1.014Q contain four vulnerabilities in the bundled 7-Zip component, including heap-based buffer overflow, NULL pointer dereference, link following, and path traversal flaws. These issues could allow local attackers to cause denial-of-service conditions, tamper with data, or execute arbitrary code when a user decompresses a specially crafted archive file. Mitsubishi Electric has released fixed version 1.015R or later, and recommends network segmentation and access controls for users unable to update immediately.
Why it matters: Critical manufacturing environments using affected versions should prioritize patching to version 1.015R or later to prevent arbitrary code execution through archive decompression attacks.
- Source published
- First seen by Cybersecurity Tracker