Vulnerability Description
Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '05' to '19' and R04/08/16/32/120(EN)CPU Firmware versions from '35' to '51') allows a remote attacker to cause an error in a CPU unit via a specially crafted HTTP packet, which may lead to a denial-of-service (DoS) condition in execution of the program and its communication.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mitsubishielectric | Melsec Iq-R00 Firmware | >= 05, <= 19 |
| Mitsubishielectric | Melsec Iq-R00 | - |
| Mitsubishielectric | Melsec Iq-R01 Firmware | >= 05, <= 19 |
| Mitsubishielectric | Melsec Iq-R01 | - |
| Mitsubishielectric | Melsec Iq-R02 Firmware | >= 05, <= 19 |
| Mitsubishielectric | Melsec Iq-R02 | - |
| Mitsubishielectric | Melsec Iq-R04 Firmware | >= 35, <= 51 |
| Mitsubishielectric | Melsec Iq-R04 | - |
| Mitsubishielectric | Melsec Iq-R16 Firmware | >= 35, <= 51 |
| Mitsubishielectric | Melsec Iq-R16 | - |
| Mitsubishielectric | Melsec Iq-R08 Firmware | >= 35, <= 51 |
| Mitsubishielectric | Melsec Iq-R08 | - |
| Mitsubishielectric | Melsec Iq-R32 Firmware | >= 35, <= 51 |
| Mitsubishielectric | Melsec Iq-R32 | - |
| Mitsubishielectric | Melsec Iq-R120 Firmware | >= 35, <= 51 |
| Mitsubishielectric | Melsec Iq-R120 | - |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/jp/JVN44764844/index.htmlThird Party Advisory
- https://jvn.jp/jp/JVN44764844/index.htmlThird Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-20-317-01Third Party AdvisoryUS Government Resource
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-015_en.pdfMitigationVendor Advisory
- https://jvn.jp/en/jp/JVN44764844/index.htmlThird Party Advisory
- https://jvn.jp/jp/JVN44764844/index.htmlThird Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-20-317-01Third Party AdvisoryUS Government Resource
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-015_en.pdfMitigationVendor Advisory
FAQ
What is CVE-2020-5666?
CVE-2020-5666 is a vulnerability with a CVSS score of 7.5 (HIGH). Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '05' to '19' and R04/08/16/32/120(EN)CPU Firmware versions from '35' to '51') all...
How severe is CVE-2020-5666?
CVE-2020-5666 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-5666?
Check the references section above for vendor advisories and patch information. Affected products include: Mitsubishielectric Melsec Iq-R00 Firmware, Mitsubishielectric Melsec Iq-R00, Mitsubishielectric Melsec Iq-R01 Firmware, Mitsubishielectric Melsec Iq-R01, Mitsubishielectric Melsec Iq-R02 Firmware.