Description
Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over the network. This denial of service attack exposes Improper Input Validation. After halting, physical access to the PLC is required in order to restore production, and the device state is lost. This is related to R04CPU, RJ71GF11-T2, R04CPU, and RJ71GF11-T2.
Published: 2020-11-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-8808 Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over the network. This denial of service attack exposes Improper Input Validation. After halting, physical access to the PLC is required in order to restore production, and the device state is lost. This is related to R04CPU, RJ71GF11-T2, R04CPU, and RJ71GF11-T2.
History

No history.

Subscriptions

Mitsubishielectric R00cpu R00cpu Firmware R01cpu R01cpu Firmware R02cpu R02cpu Firmware R04cpu R04cpu Firmware R08cpu R08cpu Firmware R08pcpu R08pcpu Firmware R08sfcpu R08sfcpu Firmware R120cpu R120cpu Firmware R120pcpu R120pcpu Firmware R120sfcpu R120sfcpu Firmware R16cpu R16cpu Firmware R16mtcpu R16mtcpu Firmware R16pcpu R16pcpu Firmware R16sfcpu R16sfcpu Firmware R32cpu R32cpu Firmware R32mtcpu R32mtcpu Firmware R32pcpu R32pcpu Firmware R32sfcpu R32sfcpu Firmware R64mtcpu R64mtcpu Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T13:45:33.224Z

Reserved: 2020-08-04T00:00:00.000Z

Link: CVE-2020-16850

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-11-30T22:15:10.840

Modified: 2024-11-21T05:07:16.033

Link: CVE-2020-16850

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses