CVE-2020-16850: Input Validation
Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over the network. This denial of service attack exposes Improper Input Validation. After halting, physical access to the PLC is required in order to restore production, and the device state is lost. This is related to R04CPU, RJ71GF11-T2, R04CPU, and RJ71GF11-T2.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-16850.
What is the severity rating of CVE-2020-16850?
CVE-2020-16850 has a severity rating of 7.5 (high).
What is the affected software?
The affected software is Mitsubishi MELSEC iQ-R Series PLCs with firmware versions up to 49.
How can an attacker exploit this vulnerability?
An unauthenticated attacker can exploit this vulnerability by sending a crafted packet over the network to halt the industrial process.
How can I mitigate this vulnerability?
To mitigate this vulnerability, it is recommended to update the firmware of the affected Mitsubishi MELSEC iQ-R Series PLCs to version 20 or higher.