T-Mobile and Other American Telecoms Targeted by Chinese Threat Actors in Espionage Campaign
November 19, 2024Multiple Apache Tomcat Vulnerabilities
November 19, 2024T-Mobile and Other American Telecoms Targeted by Chinese Threat Actors in Espionage Campaign
November 19, 2024Multiple Apache Tomcat Vulnerabilities
November 19, 2024Severity
High
Analysis Summary
CVE-2024-8403
Improper Validation of Specified Type of Input vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET versions 1.100 and later and FX5-ENET/IP versions 1.100 to 1.104 allows a remote attacker to cause a Denial of Service condition in Ethernet communication of the products by sending specially crafted SLMP packets.
Impact
- Denial of Service
Indicators of Compromise
CVE
- CVE-2024-8403
Affected Vendors
Affected Products
- Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET - 1.100 and later
- Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP - 1.100 to 1.104
Remediation
Refer to Mitsubishi Electric Website for patch, upgrade, or suggested workaround information.