Mitsubishi Electric Corporation's vulnerability portfolio centers on industrial control systems and programmable logic controllers, particularly its MELSEC IQ-R CPU series and related automation platforms that support critical manufacturing and infrastructure operations. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes including improper input validation, authentication failures, and memory-handling flaws that are characteristic of embedded control firmware with long operational lifespans. Defenders should prioritize inventory and segmentation of affected automation equipment; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mitsubishi Electric Corporation over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25163CRITICAL Improper Input Validation vulnerability in Mitsubishi Electric MELSEC-Q Series QJ71E71-100 first 5 digits of serial number "24061" or prior, Mitsubishi Electric MELSEC-L series LJ7 | Jun 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-20595HIGH Improper Restriction of XML External Entity Reference vulnerability in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver.3.35 and prior, GB-50A Ver.3.3 | Jul 13, 2021 | 8.2 | 27 | NO | NO |
CVE-2021-20611HIGH Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, M | Dec 1, 2021 | 7.5 | 25 | NO | NO |
CVE-2021-20610HIGH Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Se | Dec 1, 2021 | 7.5 | 25 | NO | NO |
CVE-2021-20609HIGH Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120 | Dec 1, 2021 | 7.5 | 25 | NO | NO |
CVE-2021-20589HIGH Buffer access with incorrect length value vulnerability in GOT2000 series GT27 model communication driver versions 01.19.000 through 01.38.000, GT25 model communication driver vers | May 19, 2021 | 7.5 | 25 | NO | NO |
CVE-2022-33324HIGH Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series R00/01/02CPU Firmware versions "32" and prior, Mitsubishi Electric Corpora | Dec 23, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-24296HIGH Use of a Broken or Risky Cryptographic Algorithm vulnerability in Air Conditioning System G-150AD Ver. 3.21 and prior, Air Conditioning System AG-150A-A Ver. 3.21 and prior, Air Co | Jun 8, 2022 | 7.5 | 23 | NO | NO |
CVE-2021-20593HIGH Incorrect Implementation of Authentication Algorithm in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver.2.50 to Ver. 3.35, GB-50A Ver.2.50 to Ver. 3. | Jul 13, 2021 | 7.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mitsubishi Electric Corporation.
Media articles that mention a CVE ID that affects a product developed by Mitsubishi Electric Corporation — matched by CVE ID, not by vendor name.