SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-5666

Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '05' to '19' and R04/08/16/32/120(EN)CPU Firmware versions from '35' to '51') allows a remote attacker to cause an error in a CPU unit…

HIGH 7.5EPSS 8.75%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (8.75%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '05' to '19' and R04/08/16/32/120(EN)CPU Firmware versions from '35' to '51') allows a remote attacker to cause an error in a CPU unit via a specially crafted HTTP packet, which may lead to a denial-of-service (DoS) condition in execution of the program and its communication.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
8.75% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-400
Affected
mitsubishielectric/melsec iq-r00 firmware · mitsubishielectric/melsec iq-r01 firmware · mitsubishielectric/melsec iq-r02 firmware · mitsubishielectric/melsec iq-r04 firmware · mitsubishielectric/melsec iq-r16 firmware · mitsubishielectric/melsec iq-r08 firmware · mitsubishielectric/melsec iq-r32 firmware · mitsubishielectric/melsec iq-r120 firmware
Source
vultures@jpcert.or.jp

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.