PT-2020-13388 · Mitsubishi · Melsec Iq-R Series Plcs
Published
2020-06-10
·
Updated
2020-06-23
·
CVE-2020-13238
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Mitsubishi MELSEC iQ-R Series PLCs version 33
Description
The issue allows attackers to halt the industrial process by sending an unauthenticated crafted packet over the network, consuming excessive CPU time and resulting in a denial of service attack. After the process is halted, physical access to the PLC is required to restore production.
Recommendations
For Mitsubishi MELSEC iQ-R Series PLCs version 33, consider restricting network access to the PLC to minimize the risk of exploitation, and ensure that physical access controls are in place to facilitate restoration of production in case of an attack. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Melsec Iq-R Series Plcs