PT-2020-18502 · Mitsubishi · Melsec Iq-R Series+3

Published

2020-03-30

·

Updated

2020-04-07

·

CVE-2020-5527

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions MELSEC iQ-R series (all versions) MELSEC iQ-F series (all versions) MELSEC Q series (all versions) MELSEC L series (all versions) MELSEC F series (all versions)
Description The MELSOFT transmission port (UDP/IP) of the affected Mitsubishi Electric MELSEC series may fall into a denial-of-service (DoS) condition when it receives a massive amount of data via unspecified vectors, causing resource consumption and improper data processing. This issue only affects Ethernet communication functions.
Recommendations For MELSEC iQ-R series, restrict access to the MELSOFT transmission port (UDP/IP) to minimize the risk of exploitation. For MELSEC iQ-F series, consider disabling the Ethernet communication functions until a fix is available. For MELSEC Q series, limit the amount of data that can be received via the MELSOFT transmission port (UDP/IP) to prevent resource consumption. For MELSEC L series, avoid using the MELSOFT transmission port (UDP/IP) for critical communications until the issue is resolved. For MELSEC F series, implement traffic filtering to block massive amounts of data from reaching the MELSOFT transmission port (UDP/IP).

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5527

Affected Products

Melsec-L Series
Melsec-Q Series
Melsec Iq-F Series
Melsec Iq-R Series