HIGH · 7.5

CVE-2020-5527

When MELSOFT transmission port (UDP/IP) of Mitsubishi Electric MELSEC iQ-R series (all versions), MELSEC iQ-F series (all versions), MELSEC Q series (all versions), MELSEC L series (all versions), and...

Vulnerability Description

When MELSOFT transmission port (UDP/IP) of Mitsubishi Electric MELSEC iQ-R series (all versions), MELSEC iQ-F series (all versions), MELSEC Q series (all versions), MELSEC L series (all versions), and MELSEC F series (all versions) receives massive amount of data via unspecified vectors, resource consumption occurs and the port does not process the data properly. As a result, it may fall into a denial-of-service (DoS) condition. The vendor states this vulnerability only affects Ethernet communication functions.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
MitsubishielectricCr800-Q Firmware-
MitsubishielectricCr800-Q-
MitsubishielectricFx3G Firmware-
MitsubishielectricFx3G-
MitsubishielectricFx3Gc Firmware-
MitsubishielectricFx3Gc-
MitsubishielectricFx3S Firmware-
MitsubishielectricFx3S-
MitsubishielectricFx3U Firmware-
MitsubishielectricFx3U-
MitsubishielectricFx3Uc Firmware-
MitsubishielectricFx3Uc-
MitsubishielectricFx5U Firmware-
MitsubishielectricFx5U-
MitsubishielectricFx5Uc Firmware-
MitsubishielectricFx5Uc-
MitsubishielectricFx5Uj Firmware-
MitsubishielectricFx5Uj-
MitsubishielectricL02Cpu Firmware-
MitsubishielectricL02Cpu-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-5527?

CVE-2020-5527 is a vulnerability with a CVSS score of 7.5 (HIGH). When MELSOFT transmission port (UDP/IP) of Mitsubishi Electric MELSEC iQ-R series (all versions), MELSEC iQ-F series (all versions), MELSEC Q series (all versions), MELSEC L series (all versions), and...

How severe is CVE-2020-5527?

CVE-2020-5527 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-5527?

Check the references section above for vendor advisories and patch information. Affected products include: Mitsubishielectric Cr800-Q Firmware, Mitsubishielectric Cr800-Q, Mitsubishielectric Fx3G Firmware, Mitsubishielectric Fx3G, Mitsubishielectric Fx3Gc Firmware.