MediumPublished 2023-12-02 · 3d ago

ICSA-23-336-03 · CVE-2023-50229

MELSEC iQ-R denial of service via MELSOFT

A malformed MELSOFT packet causes the CPU to halt; recovery requires manual restart. Pre-auth, network-adjacent.

Mitigations

  1. 01Update CPU firmware ≥ 60
  2. 02Limit MELSOFT TCP/5007 to engineering subnet