7.8

CVE-2020-16850

Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over the network. This denial of service attack exposes Improper Input Validation. After halting, physical access to the PLC is required in order to restore production, and the device state is lost. This is related to R04CPU, RJ71GF11-T2, R04CPU, and RJ71GF11-T2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MitsubishielectricR00cpu Firmware Version <= 20
   MitsubishielectricR00cpu Version-
MitsubishielectricR01cpu Firmware Version <= 20
   MitsubishielectricR01cpu Version-
MitsubishielectricR02cpu Firmware Version <= 20
   MitsubishielectricR02cpu Version-
MitsubishielectricR04cpu Firmware Version <= 52
   MitsubishielectricR04cpu Version-
MitsubishielectricR08cpu Firmware Version <= 52
   MitsubishielectricR08cpu Version-
MitsubishielectricR16cpu Firmware Version <= 52
   MitsubishielectricR16cpu Version-
MitsubishielectricR32cpu Firmware Version <= 52
   MitsubishielectricR32cpu Version-
MitsubishielectricR120cpu Firmware Version <= 52
   MitsubishielectricR120cpu Version-
MitsubishielectricR08sfcpu Firmware Version <= 22
   MitsubishielectricR08sfcpu Version-
MitsubishielectricR16sfcpu Firmware Version <= 22
   MitsubishielectricR16sfcpu Version-
MitsubishielectricR32sfcpu Firmware Version <= 22
   MitsubishielectricR32sfcpu Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.52% 0.661
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.