8.6
CWE
20 400
Advisory Published
Updated

CVE-2020-16850: Input Validation

First published: Mon Nov 30 2020(Updated: )

Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over the network. This denial of service attack exposes Improper Input Validation. After halting, physical access to the PLC is required in order to restore production, and the device state is lost. This is related to R04CPU, RJ71GF11-T2, R04CPU, and RJ71GF11-T2.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Mitsubishielectric R00cpu Firmware<=20
Mitsubishielectric R00cpu
Mitsubishielectric R01cpu Firmware<=20
Mitsubishielectric R01cpu
Mitsubishielectric R02cpu Firmware<=20
Mitsubishielectric R02cpu
Mitsubishielectric R04cpu Firmware<=52
Mitsubishielectric R04cpu
Mitsubishielectric R08cpu Firmware<=52
Mitsubishielectric R08cpu
Mitsubishielectric R16cpu Firmware<=52
Mitsubishielectric R16cpu
Mitsubishielectric R32cpu Firmware<=52
Mitsubishielectric R32cpu
Mitsubishielectric R120cpu Firmware<=52
Mitsubishielectric R120cpu
Mitsubishielectric R08sfcpu Firmware<=22
Mitsubishielectric R08sfcpu
Mitsubishielectric R16sfcpu Firmware<=22
Mitsubishielectric R16sfcpu
Mitsubishielectric R32sfcpu Firmware<=22
Mitsubishielectric R32sfcpu
Mitsubishielectric R120sfcpu Firmware<=22
Mitsubishielectric R120sfcpu
Mitsubishielectric R08pcpu Firmware
Mitsubishielectric R08pcpu
Mitsubishielectric R16pcpu Firmware
Mitsubishielectric R16pcpu
Mitsubishielectric R32pcpu Firmware
Mitsubishielectric R32pcpu
Mitsubishielectric R120pcpu Firmware
Mitsubishielectric R120pcpu
Mitsubishielectric R16mtcpu Firmware
Mitsubishielectric R16mtcpu
Mitsubishielectric R32mtcpu Firmware
Mitsubishielectric R32mtcpu
Mitsubishielectric R64mtcpu Firmware
Mitsubishielectric R64mtcpu
Mitsubishi Electric R00/01/02CPU, Firmware Versions 20 and earlier
Mitsubishi Electric R04/08/16/32/120(EN)CPU, Firmware Versions 52 and earlier
Mitsubishi Electric R08/16/32/120SFCPU, Firmware Versions 22 and earlier
Mitsubishi Electric R08/16/32/120PCPU, Firmware Versions 25 and earlier

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Parent vulnerabilities

(Appears in the following advisories)

Frequently Asked Questions

  • What is the vulnerability ID for this issue?

    The vulnerability ID for this issue is CVE-2020-16850.

  • What is the severity rating of CVE-2020-16850?

    CVE-2020-16850 has a severity rating of 7.5 (high).

  • What is the affected software?

    The affected software is Mitsubishi MELSEC iQ-R Series PLCs with firmware versions up to 49.

  • How can an attacker exploit this vulnerability?

    An unauthenticated attacker can exploit this vulnerability by sending a crafted packet over the network to halt the industrial process.

  • How can I mitigate this vulnerability?

    To mitigate this vulnerability, it is recommended to update the firmware of the affected Mitsubishi MELSEC iQ-R Series PLCs to version 20 or higher.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203