Vulnerability Description
Buffer overflow vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network Interface Module First 2 digits of serial number are '02' or before, RJ71PN92 PROFINET IO Controller Module First 2 digits of serial number are '01' or before, RD81DL96 High Speed Data Logger Module First 2 digits of serial number are '08' or before, RD81MES96N MES Interface Module First 2 digits of serial number are '04' or before, and RD81OPC96 OPC UA Server Module First 2 digits of serial number are '04' or before) allows a remote unauthenticated attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mitsubishielectric | Melsec Iq-Rj71Eip91 Firmware | - |
| Mitsubishielectric | Melsec Iq-Rj71Eip91 | - |
| Mitsubishielectric | Melsec Iq-Rj71Pn92 Firmware | - |
| Mitsubishielectric | Melsec Iq-Rj71Pn92 | - |
| Mitsubishielectric | Melsec Iq-Rd81Dl96 Firmware | - |
| Mitsubishielectric | Melsec Iq-Rd81Dl96 | - |
| Mitsubishielectric | Melsec Iq-Rd81Mes96N Firmware | - |
| Mitsubishielectric | Melsec Iq-Rd81Mes96N | - |
| Mitsubishielectric | Melsec Iq-Rd81Opc96 Firmware | - |
| Mitsubishielectric | Melsec Iq-Rd81Opc96 | - |
Related Weaknesses (CWE)
References
- https://jvn.jp/vu/JVNVU92513419/index.htmlThird Party Advisory
- https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2020-012.pdfVendor Advisory
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-012_en.pdfVendor Advisory
- https://jvn.jp/vu/JVNVU92513419/index.htmlThird Party Advisory
- https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2020-012.pdfVendor Advisory
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-012_en.pdfVendor Advisory
FAQ
What is CVE-2020-5653?
CVE-2020-5653 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Buffer overflow vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network Interface Module First 2 digits of serial number are '02' or before, RJ71...
How severe is CVE-2020-5653?
CVE-2020-5653 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-5653?
Check the references section above for vendor advisories and patch information. Affected products include: Mitsubishielectric Melsec Iq-Rj71Eip91 Firmware, Mitsubishielectric Melsec Iq-Rj71Eip91, Mitsubishielectric Melsec Iq-Rj71Pn92 Firmware, Mitsubishielectric Melsec Iq-Rj71Pn92, Mitsubishielectric Melsec Iq-Rd81Dl96 Firmware.