← Back

CVE-2020-5666

nvd nist
Published: Nov 16, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '05' to '19' and R04/08/16/32/120(EN)CPU Firmware versions from '35' to '51') allows a remote attacker to cause an error in a CPU unit via a specially crafted HTTP packet, which may lead to a denial-of-service (DoS) condition in execution of the program and its communication.

Affected (8)

Melsec Iq R00 Firmware
Melsec Iq R01 Firmware
Melsec Iq R02 Firmware
Melsec Iq R04 Firmware
Melsec Iq R16 Firmware
Melsec Iq R08 Firmware
Melsec Iq R32 Firmware
Melsec Iq R120 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 05 to 19
Running on/withPlatform Versions
Mitsubishielectric
Melsec Iq R00
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 05 to 19
Running on/withPlatform Versions
Mitsubishielectric
Melsec Iq R01
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 05 to 19
Running on/withPlatform Versions
Mitsubishielectric
Melsec Iq R02
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 35 to 51
Running on/withPlatform Versions
Mitsubishielectric
Melsec Iq R04
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 35 to 51
Running on/withPlatform Versions
Mitsubishielectric
Melsec Iq R16
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 35 to 51
Running on/withPlatform Versions
Mitsubishielectric
Melsec Iq R08
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 35 to 51
Running on/withPlatform Versions
Mitsubishielectric
Melsec Iq R32
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 35 to 51
Running on/withPlatform Versions
Mitsubishielectric
Melsec Iq R120
All versions

References (8)

Source: vultures@jpcert.or.jp
Third Party Advisory
Source: vultures@jpcert.or.jp
Third Party Advisory
Source: vultures@jpcert.or.jp
Third Party AdvisoryUS Government Resource
Source: vultures@jpcert.or.jp
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory

Timeline

No history available yet.