PT-2020-5562 · Mitsubishi · Melsec Iq-R Series Plcs
Published
2020-11-30
·
Updated
2021-07-21
·
CVE-2020-16850
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Mitsubishi MELSEC iQ-R Series PLCs version 49
Description
The issue allows an unauthenticated attacker to halt the industrial process by sending a crafted packet over the network, exposing Improper Input Validation. This results in a denial of service attack. After the process is halted, physical access to the PLC is required to restore production, and the device state is lost. The issue is related to specific models including R04CPU and RJ71GF11-T2.
Recommendations
For Mitsubishi MELSEC iQ-R Series PLCs version 49, consider implementing network segmentation to restrict access to the PLC and limit the potential impact of a denial of service attack. As a temporary workaround, restrict network access to the PLC to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Melsec Iq-R Series Plcs