First published: Mon Feb 17 2020(Updated: )
Mitsubishi Electric MELSEC C Controller Module and MELIPC Series MI5000 MELSEC-Q Series C Controller Module(Q24DHCCPU-V, Q24DHCCPU-VG User Ethernet port (CH1, CH2): First 5 digits of serial number 21121 or before), MELSEC iQ-R Series C Controller Module / C Intelligent Function Module(R12CCPU-V Ethernet port (CH1, CH2): First 2 digits of serial number 11 or before, and RD55UP06-V Ethernet port: First 2 digits of serial number 08 or before), and MELIPC Series MI5000(MI5122-VW Ethernet port (CH1): First 2 digits of serial number 03 or before, or the firmware version 03 or before) allow remote attackers to cause a denial of service and/or malware being executed via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishielectric Mi5122-vw Firmware | <=03 | |
Mitsubishielectric Mi5122-vw | ||
Mitsubishielectric Q24dhccpu-v Firmware | <=21121 | |
Mitsubishielectric Q24dhccpu-v | ||
Mitsubishielectric Q24dhccpu-vg Firmware | <=21121 | |
Mitsubishielectric Q24dhccpu-vg | ||
Mitsubishielectric R12ccpu-v Firmware | <=11 | |
Mitsubishielectric R12ccpu-v | ||
Mitsubishielectric Rd55up06-v Firmware | <=08 | |
Mitsubishielectric Rd55up06-v |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5531 is a vulnerability in Mitsubishi Electric MELSEC C Controller Module and MELIPC Series MI5000 MELSEC-Q Series C Controller.
CVE-2020-5531 has a severity rating of 9.8 (Critical).
CVE-2020-5531 affects Mitsubishi Electric MI5122-VW firmware up to version 03 and Q24DHCCPU-V/ VG firmware with serial number 21121 or before.
No, Mitsubishi Electric MI5122-VW and Q24DHCCPU-V/ VG hardware are not vulnerable to CVE-2020-5531.
You can find more information about CVE-2020-5531 on the official Mitsubishi Electric PSIRT website and JVN Vulnerability Database.