Description
Uncontrolled resource consumption vulnerability in Ethernet Port on MELSEC iQ-R, Q and L series CPU modules (R 00/01/02 CPU firmware versions '20' and earlier, R 04/08/16/32/120 (EN) CPU firmware versions '52' and earlier, R 08/16/32/120 SFCPU firmware versions '22' and earlier, R 08/16/32/120 PCPU all versions, R 08/16/32/120 PSFCPU all versions, R 16/32/64 MTCPU all versions, Q03 UDECPU, Q 04/06/10/13/20/26/50/100 UDEHCPU serial number '22081' and earlier , Q 03/04/06/13/26 UDVCPU serial number '22031' and earlier, Q 04/06/13/26 UDPVCPU serial number '22031' and earlier, Q 172/173 DCPU all versions, Q 172/173 DSCPU all versions, Q 170 MCPU all versions, Q 170 MSCPU all versions, L 02/06/26 CPU (-P) and L 26 CPU - (P) BT all versions) allows a remote unauthenticated attacker to stop the Ethernet communication functions of the products via a specially crafted packet, which may lead to a denial of service (DoS) condition .
Published: 2020-10-30
Score: 7.5 High
EPSS: 3.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-26813 Uncontrolled resource consumption vulnerability in Ethernet Port on MELSEC iQ-R, Q and L series CPU modules (R 00/01/02 CPU firmware versions '20' and earlier, R 04/08/16/32/120 (EN) CPU firmware versions '52' and earlier, R 08/16/32/120 SFCPU firmware versions '22' and earlier, R 08/16/32/120 PCPU all versions, R 08/16/32/120 PSFCPU all versions, R 16/32/64 MTCPU all versions, Q03 UDECPU, Q 04/06/10/13/20/26/50/100 UDEHCPU serial number '22081' and earlier , Q 03/04/06/13/26 UDVCPU serial number '22031' and earlier, Q 04/06/13/26 UDPVCPU serial number '22031' and earlier, Q 172/173 DCPU all versions, Q 172/173 DSCPU all versions, Q 170 MCPU all versions, Q 170 MSCPU all versions, L 02/06/26 CPU (-P) and L 26 CPU - (P) BT all versions) allows a remote unauthenticated attacker to stop the Ethernet communication functions of the products via a specially crafted packet, which may lead to a denial of service (DoS) condition .
History

No history.

Subscriptions

Mitsubishielectric Melsec Iq-r00cpu Melsec Iq-r00cpu Firmware Melsec Iq-r01cpu Melsec Iq-r01cpu Firmware Melsec Iq-r02cpu Melsec Iq-r02cpu Firmware Melsec Iq-r04encpu Melsec Iq-r04encpu Firmware Melsec Iq-r08encpu Melsec Iq-r08encpu Firmware Melsec Iq-r08pcpu Melsec Iq-r08pcpu Firmware Melsec Iq-r08psfcpu Melsec Iq-r08psfcpu Firmware Melsec Iq-r08sfcpu Melsec Iq-r08sfcpu Firmware Melsec Iq-r120encpu Melsec Iq-r120encpu Firmware Melsec Iq-r120pcpu Melsec Iq-r120pcpu Firmware Melsec Iq-r120psfcpu Melsec Iq-r120psfcpu Firmware Melsec Iq-r120sfcpu Melsec Iq-r120sfcpu Firmware Melsec Iq-r16encpu Melsec Iq-r16encpu Firmware Melsec Iq-r16mtcpu Melsec Iq-r16mtcpu Firmware Melsec Iq-r16pcpu Melsec Iq-r16pcpu Firmware Melsec Iq-r16psfcpu Melsec Iq-r16psfcpu Firmware Melsec Iq-r16sfcpu Melsec Iq-r16sfcpu Firmware Melsec Iq-r32encpu Melsec Iq-r32encpu Firmware Melsec Iq-r32mtcpu Melsec Iq-r32mtcpu Firmware Melsec Iq-r32pcpu Melsec Iq-r32pcpu Firmware Melsec Iq-r32psfcpu Melsec Iq-r32psfcpu Firmware Melsec Iq-r32sfcpu Melsec Iq-r32sfcpu Firmware Melsec Iq-r64mtcpu Melsec Iq-r64mtcpu Firmware Melsec L02cpu-p Melsec L02cpu-p Firmware Melsec L06cpu-p Melsec L06cpu-p Firmware Melsec L26cpu-p Melsec L26cpu-p Firmware Melsec L26cpu-pbt Melsec L26cpu-pbt Firmware Melsec Q-q03udecpu Melsec Q-q03udecpu Firmware Melsec Q-q03udvcpu Melsec Q-q03udvcpu Firmware Melsec Q-q04udehcpu Melsec Q-q04udehcpu Firmware Melsec Q-q04udpvcpu Melsec Q-q04udpvcpu Firmware Melsec Q-q04udvcpu Melsec Q-q04udvcpu Firmware Melsec Q-q06udehcpu Melsec Q-q06udehcpu Firmware Melsec Q-q06udpvcpu Melsec Q-q06udpvcpu Firmware Melsec Q-q100udehcpu Melsec Q-q100udehcpu Firmware Melsec Q-q10udehcpu Melsec Q-q10udehcpu Firmware Melsec Q-q13udehcpu Melsec Q-q13udehcpu Firmware Melsec Q-q13udpvcpu Melsec Q-q13udpvcpu Firmware Melsec Q-q13udvcpu Melsec Q-q13udvcpu Firmware Melsec Q-q170mcpu Melsec Q-q170mcpu Firmware Melsec Q-q170mscpu-s1 Melsec Q-q170mscpu-s1 Firmware Melsec Q-q172dcpu-s1 Melsec Q-q172dcpu-s1 Firmware Melsec Q-q172dscpu Melsec Q-q172dscpu Firmware Melsec Q-q173dcpu-s1 Melsec Q-q173dcpu-s1 Firmware Melsec Q-q173dscpu Melsec Q-q173dscpu Firmware Melsec Q-q20udehcpu Melsec Q-q20udehcpu Firmware Melsec Q-q26udehcpu Melsec Q-q26udehcpu Firmware Melsec Q-q26udpvcpu Melsec Q-q26udpvcpu Firmware Melsec Q-q26udvcpu Melsec Q-q26udvcpu Firmware Melsec Q-q50udehcpu Melsec Q-q50udehcpu Firmware Melsec Q-qmr-mq100 Melsec Q-qmr-mq100 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2024-08-04T08:39:25.481Z

Reserved: 2020-01-06T00:00:00.000Z

Link: CVE-2020-5652

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-11-02T21:15:33.697

Modified: 2024-11-21T05:34:25.693

Link: CVE-2020-5652

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses