CVE-2020-13238: High severity mitsubishi electric melsec iq-r00cpu firmware vulnerability
Mitsubishi MELSEC iQ-R Series PLCs with firmware 33 allow attackers to halt the industrial process by sending an unauthenticated crafted packet over the network, because this denial of service attack consumes excessive CPU time. After halting, physical access to the PLC is required in order to restore production.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-13238?
CVE-2020-13238 is classified as a high severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2020-13238?
To mitigate CVE-2020-13238, updating the firmware of the Mitsubishi MELSEC iQ-R Series PLCs to a version that includes the security patch is necessary.
What causes the vulnerability CVE-2020-13238?
CVE-2020-13238 is caused by the PLCs accepting unauthenticated crafted packets that can exhaust CPU resources.
What are the risks associated with CVE-2020-13238?
Exploiting CVE-2020-13238 can lead to halting critical industrial processes, requiring physical access to restore functionality.
Which devices are affected by CVE-2020-13238?
CVE-2020-13238 affects Mitsubishi MELSEC iQ-R Series PLCs with specific firmware versions of 33 and below.