CVE-2021-20611
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, MELSEC iQ-R Series R08/16/32/120PCPU, MELSEC iQ-R Series R08/16/32/120PSFCPU, MELSEC iQ-R Series R16/32/64MTCPU, MELSEC iQ-R Series R12CCPU-V, MELSEC Q Series Q03UDECPU, MELSEC Q Series Q04/06/10/13/20/26/50/100UDEHCPU, MELSEC Q Series Q03/04/06/13/26UDVCPU, MELSEC Q Series Q04/06/13/26UDPVCPU, MELSEC Q Series Q12DCCPU-V, MELSEC Q Series Q24DHCCPU-V(G), MELSEC Q Series Q24/26DHCCPU-LS, MELSEC Q Series MR-MQ100, MELSEC Q Series Q172/173DCPU-S1, MELSEC Q Series Q172/173DSCPU, MELSEC Q Series Q170MCPU, MELSEC Q Series Q170MSCPU(-S1), MELSEC L Series L02/06/26CPU(-P), MELSEC L Series L26CPU-(P)BT and MELIPC Series MI5122-VW allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by sending specially crafted packets. System reset is required for recovery.
Affected (59)
Products: Mitsubishi: Melsec Iq R R00 Cpu Firmware, Melsec Iq R R01 Cpu Firmware, Melsec Iq R R02 Cpu Firmware, Melsec Iq R R04 Cpu Firmware, Melsec Iq R R08 Cpu Firmware, Melsec Iq R R120 Cpu Firmware, Melsec Iq R R16 Cpu Firmware, Melsec Iq R R32 Cpu Firmware, Melsec Iq R R04 Pcpu Firmware, Melsec Iq R R08 Pcpu Firmware, Melsec Iq R R16 Pcpu Firmware, Melsec Iq R R32 Pcpu Firmware, Melsec Iq R R120 Pcpu Firmware, Melsec Iq R R08 Sfcpu Firmware, Melsec Iq R R16 Sfcpu Firmware, Melsec Iq R R32 Sfcpu Firmware, Melsec Iq R R120 Sfcpu Firmware, Melsec Iq R R16 Mtcpu Firmware, Melsec Iq R R32 Mtcpu Firmware, Melsec Iq R R64 Mtcpu Firmware, Melsec Iq R R12 Ccpu V Firmware, Melsec Q03udecpu Firmware, Melsec Q04udecpu Firmware, Melsec Q06udecpu Firmware, Melsec Q10udecpu Firmware, Melsec Q13udecpu Firmware, Melsec Q20udecpu Firmware, Melsec Q26udecpu Firmware, Melsec Q50udecpu Firmware, Melsec Q100udecpu Firmware, Melsec Q03udvcpu Firmware, Melsec Q04udvcpu Firmware, Melsec Q06udvcpu Firmware, Melsec Q13udvcpu Firmware, Melsec Q26udvcpu Firmware, Melsec Q04udpvcpu Firmware, Melsec Q06udpvcpu Firmware, Melsec Q13udpvcpu Firmware, Melsec Q26udpvcpu Firmware, Melsec Q12dccpu V Firmware, Melsec Q24dhccpu V(g) Firmware, Melsec Q24dhccpu Ls Firmware, Melsec Q26dhccpu Ls Firmware, Melsec Mr Mq100 Firmware, Melsec Q172dcpu S1 Firmware, Melsec Q173dcpu S1 Firmware, Melsec Q172dscpu Firmware, Melsec Q173dscpu Firmware, Melsec Q170mscpu( S1) Firmware, Melsec Q170mcpu Firmware, Melipc Mi5122 Vw Firmware, Melsec L26cpu (p)bt Firmware, Melsec L26cpu( P) Firmware, Melsec L06cpu( P) Firmware, Melsec L02cpu( P) Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 24 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R00 Cpu | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 24 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R01 Cpu | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 24 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R02 Cpu | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 57 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R04 Cpu | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 57 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R08 Cpu | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 57 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 57 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 57 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 29 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R04 Pcpu | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 29 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R08 Pcpu | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 29 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R16 Pcpu | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 29 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R32 Pcpu | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 29 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R120 Pcpu | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R08 Sfcpu | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R16 Sfcpu | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R32 Sfcpu | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R120 Sfcpu | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R16 Mtcpu | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R32 Mtcpu | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R64 Mtcpu | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R12 Ccpu V | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q03udecpu | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q04udecpu | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q06udecpu | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q10udecpu | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q13udecpu | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q20udecpu | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q26udecpu | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q50udecpu | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q100udecpu | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q03udvcpu | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q04udvcpu | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q06udvcpu | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q13udvcpu | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q26udvcpu | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q04udpvcpu | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q06udpvcpu | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q13udpvcpu | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q26udpvcpu | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q12dccpu V | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q24dhccpu V(g) | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q24dhccpu Ls | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q26dhccpu Ls | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Mr Mq100 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q172dcpu S1 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q173dcpu S1 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q172dscpu | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q173dscpu | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q170mscpu( S1) | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Q170mcpu | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melipc Mi5122 Vw | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec L26cpu (p)bt | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec L26cpu( P) | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec L06cpu( P) | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec L02cpu( P) | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R08 Cpu | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R16 Cpu | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R32 Cpu | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Melsec Iq R R120 Cpu | All versions |
References (6)
Source: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Third Party Advisory
Source: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Third Party AdvisoryUS Government Resource
Source: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.