// For flags

CVE-2020-5666

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '05' to '19' and R04/08/16/32/120(EN)CPU Firmware versions from '35' to '51') allows a remote attacker to cause an error in a CPU unit via a specially crafted HTTP packet, which may lead to a denial-of-service (DoS) condition in execution of the program and its communication.

Una vulnerabilidad de consumo de recursos no controlado en MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versiones desde "05" hasta "19" y R04/08/16/32/120(EN)CPU Firmware versiones desde "35" hasta "51"), permite a un atacante remoto causar un error en una unidad de CPU por medio de un paquete HTTP especialmente diseñado, lo que puede conllevar a una condición de denegación de servicio (DoS) en la ejecución del programa y su comunicación

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-01-06 CVE Reserved
  • 2020-11-16 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-09-05 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-400: Uncontrolled Resource Consumption
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mitsubishielectric
Search vendor "Mitsubishielectric"
Melsec Iq-r00 Firmware
Search vendor "Mitsubishielectric" for product "Melsec Iq-r00 Firmware"
>= 05 <= 19
Search vendor "Mitsubishielectric" for product "Melsec Iq-r00 Firmware" and version " >= 05 <= 19"
-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
Melsec Iq-r00
Search vendor "Mitsubishielectric" for product "Melsec Iq-r00"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
Melsec Iq-r01 Firmware
Search vendor "Mitsubishielectric" for product "Melsec Iq-r01 Firmware"
>= 05 <= 19
Search vendor "Mitsubishielectric" for product "Melsec Iq-r01 Firmware" and version " >= 05 <= 19"
-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
Melsec Iq-r01
Search vendor "Mitsubishielectric" for product "Melsec Iq-r01"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
Melsec Iq-r02 Firmware
Search vendor "Mitsubishielectric" for product "Melsec Iq-r02 Firmware"
>= 05 <= 19
Search vendor "Mitsubishielectric" for product "Melsec Iq-r02 Firmware" and version " >= 05 <= 19"
-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
Melsec Iq-r02
Search vendor "Mitsubishielectric" for product "Melsec Iq-r02"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
Melsec Iq-r04 Firmware
Search vendor "Mitsubishielectric" for product "Melsec Iq-r04 Firmware"
>= 35 <= 51
Search vendor "Mitsubishielectric" for product "Melsec Iq-r04 Firmware" and version " >= 35 <= 51"
-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
Melsec Iq-r04
Search vendor "Mitsubishielectric" for product "Melsec Iq-r04"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
Melsec Iq-r16 Firmware
Search vendor "Mitsubishielectric" for product "Melsec Iq-r16 Firmware"
>= 35 <= 51
Search vendor "Mitsubishielectric" for product "Melsec Iq-r16 Firmware" and version " >= 35 <= 51"
-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
Melsec Iq-r16
Search vendor "Mitsubishielectric" for product "Melsec Iq-r16"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
Melsec Iq-r08 Firmware
Search vendor "Mitsubishielectric" for product "Melsec Iq-r08 Firmware"
>= 35 <= 51
Search vendor "Mitsubishielectric" for product "Melsec Iq-r08 Firmware" and version " >= 35 <= 51"
-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
Melsec Iq-r08
Search vendor "Mitsubishielectric" for product "Melsec Iq-r08"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
Melsec Iq-r32 Firmware
Search vendor "Mitsubishielectric" for product "Melsec Iq-r32 Firmware"
>= 35 <= 51
Search vendor "Mitsubishielectric" for product "Melsec Iq-r32 Firmware" and version " >= 35 <= 51"
-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
Melsec Iq-r32
Search vendor "Mitsubishielectric" for product "Melsec Iq-r32"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
Melsec Iq-r120 Firmware
Search vendor "Mitsubishielectric" for product "Melsec Iq-r120 Firmware"
>= 35 <= 51
Search vendor "Mitsubishielectric" for product "Melsec Iq-r120 Firmware" and version " >= 35 <= 51"
-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
Melsec Iq-r120
Search vendor "Mitsubishielectric" for product "Melsec Iq-r120"
--
Safe