7.8
CVE-2021-20611
- EPSS 0.43%
- Veröffentlicht 01.12.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 05:46:52
- Quelle Mitsubishielectric.Psirt@yd.Mi
- CVE-Watchlists
- Unerledigt
Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, MELSEC iQ-R Series R08/16/32/120PCPU, MELSEC iQ-R Series R08/16/32/120PSFCPU, MELSEC iQ-R Series R16/32/64MTCPU, MELSEC iQ-R Series R12CCPU-V, MELSEC Q Series Q03UDECPU, MELSEC Q Series Q04/06/10/13/20/26/50/100UDEHCPU, MELSEC Q Series Q03/04/06/13/26UDVCPU, MELSEC Q Series Q04/06/13/26UDPVCPU, MELSEC Q Series Q12DCCPU-V, MELSEC Q Series Q24DHCCPU-V(G), MELSEC Q Series Q24/26DHCCPU-LS, MELSEC Q Series MR-MQ100, MELSEC Q Series Q172/173DCPU-S1, MELSEC Q Series Q172/173DSCPU, MELSEC Q Series Q170MCPU, MELSEC Q Series Q170MSCPU(-S1), MELSEC L Series L02/06/26CPU(-P), MELSEC L Series L26CPU-(P)BT and MELIPC Series MI5122-VW allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by sending specially crafted packets. System reset is required for recovery.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mitsubishi ≫ Melsec Iq-r R00 Cpu Firmware Version <= 24
Mitsubishi ≫ Melsec Iq-r R01 Cpu Firmware Version <= 24
Mitsubishi ≫ Melsec Iq-r R02 Cpu Firmware Version <= 24
Mitsubishi ≫ Melsec Iq-r R04 Cpu Firmware Version <= 57
Mitsubishi ≫ Melsec Iq-r R08 Cpu Firmware Version <= 57
Mitsubishi ≫ Melsec Iq-r R120 Cpu Firmware Version <= 57
Mitsubishi ≫ Melsec Iq-r R16 Cpu Firmware Version <= 57
Mitsubishi ≫ Melsec Iq-r R32 Cpu Firmware Version <= 57
Mitsubishi ≫ Melsec Iq-r R04 Pcpu Firmware Version <= 29
Mitsubishi ≫ Melsec Iq-r R08 Pcpu Firmware Version <= 29
Mitsubishi ≫ Melsec Iq-r R16 Pcpu Firmware Version <= 29
Mitsubishi ≫ Melsec Iq-r R32 Pcpu Firmware Version <= 29
Mitsubishi ≫ Melsec Iq-r R120 Pcpu Firmware Version <= 29
Mitsubishi ≫ Melsec Q03udvcpu Firmware Version-
Mitsubishi ≫ Melsec Q04udvcpu Firmware Version-
Mitsubishi ≫ Melsec Q06udvcpu Firmware Version-
Mitsubishi ≫ Melsec Q13udvcpu Firmware Version-
Mitsubishi ≫ Melsec Q26udvcpu Firmware Version-
Mitsubishi ≫ Melsec Q04udpvcpu Firmware Version-
Mitsubishi ≫ Melsec Q06udpvcpu Firmware Version-
Mitsubishi ≫ Melsec Q13udpvcpu Firmware Version-
Mitsubishi ≫ Melsec Q26udpvcpu Firmware Version-
Mitsubishi ≫ Melsec Q26dhccpu-ls Firmware Version-
Mitsubishi ≫ Melsec Q173dscpu Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.43% | 0.621 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| nvd@nist.gov | 7.8 | 10 | 6.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:C
|
| Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.