7.8

CVE-2020-5668

Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series modules (R00/01/02CPU firmware version '19' and earlier, R04/08/16/32/120 (EN) CPU firmware version '51' and earlier, R08/16/32/120SFCPU firmware version '22' and earlier, R08/16/32/120PCPU firmware version '25' and earlier, R08/16/32/120PSFCPU firmware version '06' and earlier, RJ71EN71 firmware version '47' and earlier, RJ71GF11-T2 firmware version '47' and earlier, RJ72GF15-T2 firmware version '07' and earlier, RJ71GP21-SX firmware version '47' and earlier, RJ71GP21S-SX firmware version '47' and earlier, and RJ71GN11-T2 firmware version '11' and earlier) allows a remote unauthenticated attacker to cause an error in a CPU unit and cause a denial-of-service (DoS) condition in execution of the program and its communication, or to cause a denial-of-service (DoS) condition in communication via the unit by receiving a specially crafted SLMP packet
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MitsubishielectricR00cpu Firmware Version <= 19
   MitsubishielectricR00cpu Version-
MitsubishielectricR01cpu Firmware Version <= 19
   MitsubishielectricR01cpu Version-
MitsubishielectricR02cpu Firmware Version <= 19
   MitsubishielectricR02cpu Version-
MitsubishielectricR04cpu Firmware Version <= 51
   MitsubishielectricR04cpu Version-
MitsubishielectricR08cpu Firmware Version <= 51
   MitsubishielectricR08cpu Version-
MitsubishielectricR16cpu Firmware Version <= 51
   MitsubishielectricR16cpu Version-
MitsubishielectricR32cpu Firmware Version <= 51
   MitsubishielectricR32cpu Version-
MitsubishielectricR120cpu Firmware Version <= 51
   MitsubishielectricR120cpu Version-
MitsubishielectricR08sfcpu Firmware Version <= 22
   MitsubishielectricR08sfcpu Version-
MitsubishielectricR16sfcpu Firmware Version <= 22
   MitsubishielectricR16sfcpu Version-
MitsubishielectricR32sfcpu Firmware Version <= 22
   MitsubishielectricR32sfcpu Version-
MitsubishielectricR08pcpu Firmware Version <= 25
   MitsubishielectricR08pcpu Version-
MitsubishielectricR16pcpu Firmware Version <= 25
   MitsubishielectricR16pcpu Version-
MitsubishielectricR32pcpu Firmware Version <= 25
   MitsubishielectricR32pcpu Version-
MitsubishielectricR120pcpu Firmware Version <= 25
   MitsubishielectricR120pcpu Version-
MitsubishielectricRj71en71 Firmware Version <= 47
   MitsubishielectricRj71en71 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.12% 0.863
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.