// For flags

CVE-2021-20591

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R00/01/02CPU all versions, R04/08/16/32/120(EN)CPU all versions, R08/16/32/120SFCPU all versions, R08/16/32/120PCPU all versions, R08/16/32/120PSFCPU all versions) allows a remote unauthenticated attacker to prevent legitimate clients from connecting to the MELSOFT transmission port (TCP/IP) by not closing a connection properly, which may lead to a denial of service (DoS) condition.

Una vulnerabilidad de Consumo Incontrolado de Recursos en Mitsubishi Electric MELSEC iQ-R series CPU modules (R00/01/02CPU todas las versiones, R04/08/16/32/120(ES)CPU todas las versiones, R08/16/32/120SFCPU todas las versiones, R08/16/32/120PCPU todas las versiones, R08/16/32/120PSFCPU todas las versiones) permite a un atacante remoto no autentificado impedir que clientes legítimos se conecten al puerto de transmisión de MELSOFT (TCP/IP) al no cerrar una conexión apropiadamente, lo que puede conllevar a una condición de denegación de servicio (DoS)

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-12-17 CVE Reserved
  • 2021-06-11 CVE Published
  • 2024-02-25 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-400: Uncontrolled Resource Consumption
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mitsubishielectric
Search vendor "Mitsubishielectric"
R00cpu Firmware
Search vendor "Mitsubishielectric" for product "R00cpu Firmware"
*-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
R00cpu
Search vendor "Mitsubishielectric" for product "R00cpu"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
R01cpu Firmware
Search vendor "Mitsubishielectric" for product "R01cpu Firmware"
*-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
R01cpu
Search vendor "Mitsubishielectric" for product "R01cpu"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
R02cpu Firmware
Search vendor "Mitsubishielectric" for product "R02cpu Firmware"
*-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
R02cpu
Search vendor "Mitsubishielectric" for product "R02cpu"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
R04cpu Firmware
Search vendor "Mitsubishielectric" for product "R04cpu Firmware"
*-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
R04cpu
Search vendor "Mitsubishielectric" for product "R04cpu"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
R08cpu Firmware
Search vendor "Mitsubishielectric" for product "R08cpu Firmware"
*-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
R08cpu
Search vendor "Mitsubishielectric" for product "R08cpu"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
R16cpu Firmware
Search vendor "Mitsubishielectric" for product "R16cpu Firmware"
*-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
R16cpu
Search vendor "Mitsubishielectric" for product "R16cpu"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
R32cpu Firmware
Search vendor "Mitsubishielectric" for product "R32cpu Firmware"
*-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
R32cpu
Search vendor "Mitsubishielectric" for product "R32cpu"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
R120cpu Firmware
Search vendor "Mitsubishielectric" for product "R120cpu Firmware"
*-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
R120cpu
Search vendor "Mitsubishielectric" for product "R120cpu"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
R08sfcpu Firmware
Search vendor "Mitsubishielectric" for product "R08sfcpu Firmware"
*-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
R08sfcpu
Search vendor "Mitsubishielectric" for product "R08sfcpu"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
R16sfcpu Firmware
Search vendor "Mitsubishielectric" for product "R16sfcpu Firmware"
*-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
R16sfcpu
Search vendor "Mitsubishielectric" for product "R16sfcpu"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
R32sfcpu Firmware
Search vendor "Mitsubishielectric" for product "R32sfcpu Firmware"
*-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
R32sfcpu
Search vendor "Mitsubishielectric" for product "R32sfcpu"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
R120sfcpu Firmware
Search vendor "Mitsubishielectric" for product "R120sfcpu Firmware"
*-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
R120sfcpu
Search vendor "Mitsubishielectric" for product "R120sfcpu"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
R08pcpu Firmware
Search vendor "Mitsubishielectric" for product "R08pcpu Firmware"
*-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
R08pcpu
Search vendor "Mitsubishielectric" for product "R08pcpu"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
R16pcpu Firmware
Search vendor "Mitsubishielectric" for product "R16pcpu Firmware"
*-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
R16pcpu
Search vendor "Mitsubishielectric" for product "R16pcpu"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
R32pcpu Firmware
Search vendor "Mitsubishielectric" for product "R32pcpu Firmware"
*-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
R32pcpu
Search vendor "Mitsubishielectric" for product "R32pcpu"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
R120pcpu Firmware
Search vendor "Mitsubishielectric" for product "R120pcpu Firmware"
*-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
R120pcpu
Search vendor "Mitsubishielectric" for product "R120pcpu"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
R08psfcpu Firmware
Search vendor "Mitsubishielectric" for product "R08psfcpu Firmware"
*-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
R08psfcpu
Search vendor "Mitsubishielectric" for product "R08psfcpu"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
R16psfcpu Firmware
Search vendor "Mitsubishielectric" for product "R16psfcpu Firmware"
*-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
R16psfcpu
Search vendor "Mitsubishielectric" for product "R16psfcpu"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
R32psfcpu Firmware
Search vendor "Mitsubishielectric" for product "R32psfcpu Firmware"
*-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
R32psfcpu
Search vendor "Mitsubishielectric" for product "R32psfcpu"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
R120psfcpu Firmware
Search vendor "Mitsubishielectric" for product "R120psfcpu Firmware"
*-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
R120psfcpu
Search vendor "Mitsubishielectric" for product "R120psfcpu"
--
Safe