SARA / Free Tools / CVE / CVE-2023-3346

CVE-2023-3346 — Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerabi

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition and execute arbitrary code on the product by sending specially crafted packet

CVSS
9.8 CRITICAL
EPSS
1.04% (top 22.80%)
CWE
CWE-120
Published
2023-08-03T04:00:43.294Z
Last modified
2024-12-04T15:16:48.710Z
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

01What is this vulnerability?

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition and execute arbitrary code on the product by sending specially crafted packets. In addition, system reset is required for recovery.

02Affected products

VendorProductVersions
Mitsubishi Electric CorporationMITSUBISHI CNC M800V Series M800VWSystem Number BND-2051W000 versions A8 and prior
Mitsubishi Electric CorporationMITSUBISHI CNC M800V Series M800VSSystem Number BND-2052W000 versions A8 and prior
Mitsubishi Electric CorporationMITSUBISHI CNC M80V Series M80VSystem Number BND-2053W000 versions A8 and prior
Mitsubishi Electric CorporationMITSUBISHI CNC M80V Series M80VWSystem Number BND-2054W000 versions A8 and prior
Mitsubishi Electric CorporationMITSUBISHI CNC M800 Series M800WSystem Number BND-2005W000 versions FB and prior
Mitsubishi Electric CorporationMITSUBISHI CNC M800 Series M800SSystem Number BND-2006W000 versions FB and prior
Mitsubishi Electric CorporationMITSUBISHI CNC M80 Series M80System Number BND-2007W000 versions FB and prior
Mitsubishi Electric CorporationMITSUBISHI CNC M80 Series M80WSystem Number BND-2008W000 versions FB and prior
Mitsubishi Electric CorporationMITSUBISHI CNC E80 Series E80System Number BND-2009W000 versions FB and prior
Mitsubishi Electric CorporationMITSUBISHI CNC C80 Series C80System Number BND-2036W000 versions BF and prior
Mitsubishi Electric CorporationMITSUBISHI CNC M700V Series M720VWSystem Number BND-1015W000 versions LF and prior
Mitsubishi Electric CorporationMITSUBISHI CNC M700V Series M730VWSystem Number BND-1015W000 versions LF and prior
Mitsubishi Electric CorporationMITSUBISHI CNC M700V Series M750VWSystem Number BND-1015W002 versions LF and prior
Mitsubishi Electric CorporationMITSUBISHI CNC M700V Series M720VSSystem Number BND-1012W000 versions LF and prior
Mitsubishi Electric CorporationMITSUBISHI CNC M700V Series M730VSSystem Number BND-1012W000 versions LF and prior
Mitsubishi Electric CorporationMITSUBISHI CNC M700V Series M750VSSystem Number BND-1012W002 versions LF and prior
Mitsubishi Electric CorporationMITSUBISHI CNC M70V Series M70VSystem Number BND-1018W000 versions LF and prior
Mitsubishi Electric CorporationMITSUBISHI CNC E70 Series E70System Number BND-1022W000 versions LF and prior
Mitsubishi Electric CorporationMITSUBISHI CNC IoT Unit Remote Service Gateway UnitSystem Number BND-2041W001 versions AD and prior
Mitsubishi Electric CorporationMITSUBISHI CNC IoT Unit Data Acquisition UnitSystem Number BND-2041W002 all versions

03Active exploitation status

Not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. EPSS is the best forward-looking signal — see the EPSS row above.

04Recommended remediation

05Technical details

For the full vendor write-up, exploit chains, and reference implementations, see the references list in section 09.

06Detection signatures

Open the Sigma generator with a pre-filled prompt for this CVE to draft a starting detection in your stack of choice:

Open in Sigma generator →

07Related CVEs

No directly-cited follow-up CVEs in the KB record for this advisory. The references list in section 09 carries the vendor cross-references.

08Timeline

09References

Want this in your SOAR or SIEM?
SARA's API returns EPSS, CVSS, KEV, and an analyst-grade summary in one call.
Read the API reference →