CVE-2023-1285
Signal Handler Race Condition vulnerability in Mitsubishi Electric India GC-ENET-COM whose first 2 digits of 11-digit serial number of unit are "16" allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition in Ethernet communication by sending a large number of specially crafted packets to any UDP port when GC-ENET-COM is configured as a Modbus TCP Server. The communication resumes only when the power of the main unit is turned off and on or when the GC-ENET-COM is hot-swapped from the main unit.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.43%
- CWE
- CWE-364
- Published
- 2023-04-14
- Last modified
- 2026-03-13
Affected products
- Mitsubishi Electric India GC-ENET-COM
Weakness type
Related vulnerabilities
- CVE-2026-33565 — kernel_linux_common_modules has a Race Condition vulnerability
- CVE-2026-27766 — multimedia_audio_framework has a Race Condition vulnerability
- CVE-2026-24792 — web_webview has a Race Condition vulnerability
- CVE-2025-53092 — Strapi core vulnerable to sensitive data exposure via CORS misconfiguration
- CVE-2025-4598 — Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump
- CVE-2024-6409 — Openssh: possible remote code execution due to a race condition in signal handling affecting red hat enterprise linux 9
- CVE-2024-6387 — Openssh: regresshion - race condition in ssh allows rce/dos
- CVE-2023-5676 — Eclipse OpenJ9 possible infinite busy hang