CVE-2020-16850
HIGH
7,5
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
HIGH
7,8
Source: [email protected]
Access Vector: network
Access Complexity: low
Authentication: none
Confidentiality: none
Integrity: none
Availability: complete
Description
AI Translation Available
Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over the network. This denial of service attack exposes Improper Input Validation. After halting, physical access to the PLC is required in order to restore production, and the device state is lost. This is related to R04CPU, RJ71GF11-T2, R04CPU, and RJ71GF11-T2.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0031
Percentile
0,5th
Updated
EPSS Score Trend (Last 90 Days)
20
Improper Input Validation
StableCommon Consequences
Security Scopes Affected:
Availability
Confidentiality
Integrity
Potential Impacts:
Dos: Crash, Exit, Or Restart
Dos: Resource Consumption (Cpu)
Dos: Resource Consumption (Memory)
Read Memory
Read Files Or Directories
Modify Memory
Execute Unauthorized Code Or Commands
Applicable Platforms
All platforms may be affected
400
Uncontrolled Resource Consumption
DraftCommon Consequences
Security Scopes Affected:
Availability
Access Control
Other
Potential Impacts:
Dos: Crash, Exit, Or Restart
Dos: Resource Consumption (Cpu)
Dos: Resource Consumption (Memory)
Dos: Resource Consumption (Other)
Bypass Protection Mechanism
Other
Applicable Platforms
All platforms may be affected
Operating System
R32Mtcpu Firmware by Mitsubishielectric
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mitsubishielectric:r32mtcpu_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
R32Sfcpu Firmware by Mitsubishielectric
Version Range Affected
To
22
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mitsubishielectric:r32sfcpu_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
R32Pcpu Firmware by Mitsubishielectric
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mitsubishielectric:r32pcpu_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
R04Cpu Firmware by Mitsubishielectric
Version Range Affected
To
52
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mitsubishielectric:r04cpu_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
R120Sfcpu Firmware by Mitsubishielectric
Version Range Affected
To
22
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mitsubishielectric:r120sfcpu_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
R120Cpu Firmware by Mitsubishielectric
Version Range Affected
To
52
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mitsubishielectric:r120cpu_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
R120Pcpu Firmware by Mitsubishielectric
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mitsubishielectric:r120pcpu_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
R08Pcpu Firmware by Mitsubishielectric
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mitsubishielectric:r08pcpu_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
R08Cpu Firmware by Mitsubishielectric
Version Range Affected
To
52
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mitsubishielectric:r08cpu_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
R16Sfcpu Firmware by Mitsubishielectric
Version Range Affected
To
22
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mitsubishielectric:r16sfcpu_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
R01Cpu Firmware by Mitsubishielectric
Version Range Affected
To
20
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mitsubishielectric:r01cpu_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
R00Cpu Firmware by Mitsubishielectric
Version Range Affected
To
20
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mitsubishielectric:r00cpu_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
R02Cpu Firmware by Mitsubishielectric
Version Range Affected
To
20
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mitsubishielectric:r02cpu_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
R64Mtcpu Firmware by Mitsubishielectric
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mitsubishielectric:r64mtcpu_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
R32Cpu Firmware by Mitsubishielectric
Version Range Affected
To
52
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mitsubishielectric:r32cpu_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
R16Mtcpu Firmware by Mitsubishielectric
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mitsubishielectric:r16mtcpu_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
R08Sfcpu Firmware by Mitsubishielectric
Version Range Affected
To
22
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mitsubishielectric:r08sfcpu_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
R16Cpu Firmware by Mitsubishielectric
Version Range Affected
To
52
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mitsubishielectric:r16cpu_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
R16Pcpu Firmware by Mitsubishielectric
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mitsubishielectric:r16pcpu_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://blog.scadafence.com/vulnerability-in-mitsubishi-electric-melsec-iq-r-se…
https://us-cert.cisa.gov/ics/advisories/icsa-20-282-02
https://blog.scadafence.com/vulnerability-in-mitsubishi-electric-melsec-iq-r-se…
https://us-cert.cisa.gov/ics/advisories/icsa-20-282-02