CVE-2020-16850 Information
Jun 07, 2022
cve
Description
Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over the network. This denial of service attack exposes Improper Input Validation. After halting physical access to the PLC is required in order to restore production and the device state is lost. This is related to R04CPU RJ71GF11-T2 R04CPU and RJ71GF11-T2.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Reference
https://us-cert.cisa.gov/ics/advisories/icsa-20-282-02 https://blog.scadafence.com/vulnerability-in-mitsubishi-electric-melsec-iq-r-series
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
7.5
Share on: