PT-2019-13417 · Mitsubishi · Melsec Q Series Q04/06/10/13/20/26/50/100Udehcpu+6

Tri Quach

·

Published

2019-11-13

·

Updated

2019-11-18

·

CVE-2019-13555

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU versions with serial number 21081 and prior Mitsubishi Electric MELSEC-Q Series Q04/06/13/26UDPVCPU versions with serial number 21081 and prior Mitsubishi Electric MELSEC-Q Series Q03UDECPU versions with serial number 21081 and prior Mitsubishi Electric MELSEC-Q Series Q04/06/10/13/20/26/50/100UDEHCPU versions with serial number 21081 and prior Mitsubishi Electric MELSEC-L Series L02/06/26CPU versions with serial number 21101 and prior Mitsubishi Electric MELSEC-L Series L26CPU-BT versions with serial number 21101 and prior Mitsubishi Electric MELSEC-L Series L02/06/26CPU-P versions with serial number 21101 and prior Mitsubishi Electric MELSEC-L Series L26CPU-PBT versions with serial number 21101 and prior Mitsubishi Electric MELSEC-L Series L02/06/26CPU-CM versions with serial number 21101 and prior Mitsubishi Electric MELSEC-L Series L26CPU-BT-CM versions with serial number 21101 and prior
Description A remote attacker can cause the FTP service to enter a denial-of-service condition dependent on the timing at which a remote attacker connects to the FTP server on the above CPU modules.
Recommendations For Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU with serial number 21081 and prior, consider disabling the FTP service until a patch is available. For Mitsubishi Electric MELSEC-Q Series Q04/06/13/26UDPVCPU with serial number 21081 and prior, consider disabling the FTP service until a patch is available. For Mitsubishi Electric MELSEC-Q Series Q03UDECPU with serial number 21081 and prior, consider disabling the FTP service until a patch is available. For Mitsubishi Electric MELSEC-Q Series Q04/06/10/13/20/26/50/100UDEHCPU with serial number 21081 and prior, consider disabling the FTP service until a patch is available. For Mitsubishi Electric MELSEC-L Series L02/06/26CPU with serial number 21101 and prior, consider disabling the FTP service until a patch is available. For Mitsubishi Electric MELSEC-L Series L26CPU-BT with serial number 21101 and prior, consider disabling the FTP service until a patch is available. For Mitsubishi Electric MELSEC-L Series L02/06/26CPU-P with serial number 21101 and prior, consider disabling the FTP service until a patch is available. For Mitsubishi Electric MELSEC-L Series L26CPU-PBT with serial number 21101 and prior, consider disabling the FTP service until a patch is available. For Mitsubishi Electric MELSEC-L Series L02/06/26CPU-CM with serial number 21101 and prior, consider disabling the FTP service until a patch is available. For Mitsubishi Electric MELSEC-L Series L26CPU-BT-CM with serial number 21101 and prior, consider disabling the FTP service until a patch is available.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-13555

Affected Products

Melsec L Series L02/06/26Cpu
Melsec-L Series L26Cpu-Bt
Melsec L Series L26Cpu-(P)Bt
Melsec Q Series Q03/04/06/13/26Udvcpu
Melsec Q Series Q03Udecpu
Melsec Q Series Q04/06/10/13/20/26/50/100Udehcpu
Melsec Q Series Q04/06/13/26Udpvcpu