Vulnerability Description
Mitsubishi MELSEC iQ-R Series PLCs with firmware 33 allow attackers to halt the industrial process by sending an unauthenticated crafted packet over the network, because this denial of service attack consumes excessive CPU time. After halting, physical access to the PLC is required in order to restore production.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mitsubishielectric | Melsec Iq-R00Cpu Firmware | <= 7 |
| Mitsubishielectric | Melsec Iq-R00Cpu | - |
| Mitsubishielectric | Melsec Iq-R01Cpu Firmware | <= 7 |
| Mitsubishielectric | Melsec Iq-R01Cpu | - |
| Mitsubishielectric | Melsec Iq-R02Cpu Firmware | <= 7 |
| Mitsubishielectric | Melsec Iq-R02Cpu | - |
| Mitsubishielectric | Melsec Iq-R04Cpu Firmware | <= 39 |
| Mitsubishielectric | Melsec Iq-R04Cpu | - |
| Mitsubishielectric | Melsec Iq-R08Cpu Firmware | <= 39 |
| Mitsubishielectric | Melsec Iq-R08Cpu | - |
| Mitsubishielectric | Melsec Iq-R16Cpu Firmware | <= 39 |
| Mitsubishielectric | Melsec Iq-R16Cpu | - |
| Mitsubishielectric | Melsec Iq-R32Cpu Firmware | <= 39 |
| Mitsubishielectric | Melsec Iq-R32Cpu | - |
| Mitsubishielectric | Melsec Iq-R120Cpu Firmware | <= 39 |
| Mitsubishielectric | Melsec Iq-R120Cpu | - |
| Mitsubishielectric | Melsec Iq-R08Fcpu Firmware | <= 20 |
| Mitsubishielectric | Melsec Iq-R08Fcpu | - |
| Mitsubishielectric | Melsec Iq-R16Fcpu Firmware | <= 20 |
| Mitsubishielectric | Melsec Iq-R16Fcpu | - |
Related Weaknesses (CWE)
References
- http://jvn.jp/vu/JVNVU97662844/index.htmlThird Party Advisory
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-001_en.pdfVendor Advisory
- https://www.us-cert.gov/ics/advisories/icsa-20-161-02Third Party AdvisoryUS Government Resource
- http://jvn.jp/vu/JVNVU97662844/index.htmlThird Party Advisory
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-001_en.pdfVendor Advisory
- https://www.us-cert.gov/ics/advisories/icsa-20-161-02Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2020-13238?
CVE-2020-13238 is a vulnerability with a CVSS score of 7.5 (HIGH). Mitsubishi MELSEC iQ-R Series PLCs with firmware 33 allow attackers to halt the industrial process by sending an unauthenticated crafted packet over the network, because this denial of service attack ...
How severe is CVE-2020-13238?
CVE-2020-13238 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-13238?
Check the references section above for vendor advisories and patch information. Affected products include: Mitsubishielectric Melsec Iq-R00Cpu Firmware, Mitsubishielectric Melsec Iq-R00Cpu, Mitsubishielectric Melsec Iq-R01Cpu Firmware, Mitsubishielectric Melsec Iq-R01Cpu, Mitsubishielectric Melsec Iq-R02Cpu Firmware.