7.8

CVE-2020-16850

Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over the network. This denial of service attack exposes Improper Input Validation. After halting, physical access to the PLC is required in order to restore production, and the device state is lost. This is related to R04CPU, RJ71GF11-T2, R04CPU, and RJ71GF11-T2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mitsubishielectric ≫ R00cpu Firmware Version <= 20
   Mitsubishielectric ≫ R00cpu Version -
Mitsubishielectric ≫ R01cpu Firmware Version <= 20
   Mitsubishielectric ≫ R01cpu Version -
Mitsubishielectric ≫ R02cpu Firmware Version <= 20
   Mitsubishielectric ≫ R02cpu Version -
Mitsubishielectric ≫ R04cpu Firmware Version <= 52
   Mitsubishielectric ≫ R04cpu Version -
Mitsubishielectric ≫ R08cpu Firmware Version <= 52
   Mitsubishielectric ≫ R08cpu Version -
Mitsubishielectric ≫ R16cpu Firmware Version <= 52
   Mitsubishielectric ≫ R16cpu Version -
Mitsubishielectric ≫ R32cpu Firmware Version <= 52
   Mitsubishielectric ≫ R32cpu Version -
Mitsubishielectric ≫ R120cpu Firmware Version <= 52
   Mitsubishielectric ≫ R120cpu Version -
Mitsubishielectric ≫ R08sfcpu Firmware Version <= 22
   Mitsubishielectric ≫ R08sfcpu Version -
Mitsubishielectric ≫ R16sfcpu Firmware Version <= 22
   Mitsubishielectric ≫ R16sfcpu Version -
Mitsubishielectric ≫ R32sfcpu Firmware Version <= 22
   Mitsubishielectric ≫ R32sfcpu Version -
Mitsubishielectric ≫ R120sfcpu Firmware Version <= 22
   Mitsubishielectric ≫ R120sfcpu Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.12% 0.794
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://blog.scadafence.com/vulnerability-in-mitsubishi-electric-melsec-iq-r-series
Third Party Advisory
https://us-cert.cisa.gov/ics/advisories/icsa-20-282-02
Third Party Advisory
US Government Resource