7.8
CVE-2020-16850
- EPSS 0.52%
- Veröffentlicht 30.11.2020 22:15:10
- Zuletzt bearbeitet 21.11.2024 05:07:16
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over the network. This denial of service attack exposes Improper Input Validation. After halting, physical access to the PLC is required in order to restore production, and the device state is lost. This is related to R04CPU, RJ71GF11-T2, R04CPU, and RJ71GF11-T2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mitsubishielectric ≫ R00cpu Firmware Version <= 20
Mitsubishielectric ≫ R01cpu Firmware Version <= 20
Mitsubishielectric ≫ R02cpu Firmware Version <= 20
Mitsubishielectric ≫ R04cpu Firmware Version <= 52
Mitsubishielectric ≫ R08cpu Firmware Version <= 52
Mitsubishielectric ≫ R16cpu Firmware Version <= 52
Mitsubishielectric ≫ R32cpu Firmware Version <= 52
Mitsubishielectric ≫ R120cpu Firmware Version <= 52
Mitsubishielectric ≫ R08sfcpu Firmware Version <= 22
Mitsubishielectric ≫ R16sfcpu Firmware Version <= 22
Mitsubishielectric ≫ R32sfcpu Firmware Version <= 22
Mitsubishielectric ≫ R120sfcpu Firmware Version <= 22
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.52% | 0.661 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| nvd@nist.gov | 7.8 | 10 | 6.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.