Vulnerability Details
The following vulnerabilities exist in the EZSocket library (Mitsubishi Electric Corporation) bundled with DeviceXPlorer OPC Server. If exploited, execution of a malicious program may cause a denial-of-service (DoS) condition or allow an attacker to obtain system privileges and execute arbitrary commands, and crafted packets may allow an attacker to bypass authentication and connect to the product without authorization.
| CVE ID | CVSS v3.1 Base Score | Description | References |
|---|---|---|---|
| CVE-2023-51777 | 4.4 (Medium) | Execution of a malicious program triggers a BSOD error, resulting in a denial-of-service (DoS) condition | Mitsubishi Electric 2023-020 / 2024-001 |
| CVE-2023-51778 | 4.4 (Medium) | Same as above | Same as above |
| CVE-2024-22102 | 4.4 (Medium) | Same as above | Same as above |
| CVE-2024-22103 | 4.4 (Medium) | Same as above | Same as above |
| CVE-2024-22104 | 4.4 (Medium) | Same as above | Same as above |
| CVE-2024-22105 | 4.4 (Medium) | Same as above | Same as above |
| CVE-2024-25087 | 4.4 (Medium) | Same as above | Same as above |
| CVE-2023-51776 | 4.4 (Medium) | Execution of a malicious program allows an attacker to obtain system privileges and execute arbitrary commands | Same as above |
| CVE-2024-25086 | 4.4 (Medium) | Same as above | Same as above |
| CVE-2024-25088 | 4.4 (Medium) | Same as above | Same as above |
| CVE-2024-26314 | 4.4 (Medium) | Same as above | Same as above |
| CVE-2024-22106 | 6.0 (Medium) | Execution of a malicious program causes a denial-of-service (DoS) condition and allows arbitrary command execution with system privileges | Same as above |
| CVE-2023-6942 | 7.5 (High) | Sending crafted packets allows an attacker to bypass authentication and connect to the product without authorization | Same as above |
| CVE-2023-6943 | 9.8 (Critical) | While connected, calling a function with a path to a malicious library allows execution of a malicious program | Same as above |
Affected Products
| Product | Affected Versions |
|---|---|
| DeviceXPlorer OPC Server | Ver. 5.0.0.1 - 5.4.1.1 |
| DeviceXPlorer OPC Server | Ver. 6.0.0 - 6.8.1 |
| DeviceXPlorer OPC Server | Ver. 7.0.0 - 7.3.3 |
Fixed Versions
In the fixed versions, the bundled EZSocket library has been updated from Ver. 5.4 to Ver. 5.A.
| Product | Fixed Version |
|---|---|
| DeviceXPlorer OPC Server | Ver. 6.8.2.1 |
| DeviceXPlorer OPC Server | Ver. 7.4.0.1 |
If you are using Ver. 5.x, updating to one of the fixed versions above is also required.
Contact
fa-support@takebishi.co.jp
Revision History
- 2025-03-01: Initial release