CVE-2020-16850
Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over the network.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.14%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over the network. This denial of service attack exposes Improper Input Validation. After halting, physical access to the PLC is required in order to restore production, and the device state is lost. This is related to R04CPU, RJ71GF11-T2, R04CPU, and RJ71GF11-T2.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.14% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-400
- Affected
- mitsubishielectric/r00cpu firmware · mitsubishielectric/r01cpu firmware · mitsubishielectric/r02cpu firmware · mitsubishielectric/r04cpu firmware · mitsubishielectric/r08cpu firmware · mitsubishielectric/r16cpu firmware · mitsubishielectric/r32cpu firmware · mitsubishielectric/r120cpu firmware · mitsubishielectric/r08sfcpu firmware · mitsubishielectric/r16sfcpu firmware · mitsubishielectric/r32sfcpu firmware · mitsubishielectric/r120sfcpu firmware · mitsubishielectric/r08pcpu firmware · mitsubishielectric/r16pcpu firmware · mitsubishielectric/r32pcpu firmware · mitsubishielectric/r120pcpu firmware · mitsubishielectric/r16mtcpu firmware · mitsubishielectric/r32mtcpu firmware · mitsubishielectric/r64mtcpu firmware
- Source
- cve@mitre.org
References
- https://blog.scadafence.com/vulnerability-in-mitsubishi-electric-melsec-iq-r-seriesThird Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-20-282-02Third Party Advisory, US Government Resource
- https://blog.scadafence.com/vulnerability-in-mitsubishi-electric-melsec-iq-r-seriesThird Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-20-282-02Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.