7.5
CWE
400
Advisory Published
Updated

CVE-2020-5652

First published: Mon Nov 02 2020(Updated: )

Uncontrolled resource consumption vulnerability in Ethernet Port on MELSEC iQ-R, Q and L series CPU modules (R 00/01/02 CPU firmware versions '20' and earlier, R 04/08/16/32/120 (EN) CPU firmware versions '52' and earlier, R 08/16/32/120 SFCPU firmware versions '22' and earlier, R 08/16/32/120 PCPU all versions, R 08/16/32/120 PSFCPU all versions, R 16/32/64 MTCPU all versions, Q03 UDECPU, Q 04/06/10/13/20/26/50/100 UDEHCPU serial number '22081' and earlier , Q 03/04/06/13/26 UDVCPU serial number '22031' and earlier, Q 04/06/13/26 UDPVCPU serial number '22031' and earlier, Q 172/173 DCPU all versions, Q 172/173 DSCPU all versions, Q 170 MCPU all versions, Q 170 MSCPU all versions, L 02/06/26 CPU (-P) and L 26 CPU - (P) BT all versions) allows a remote unauthenticated attacker to stop the Ethernet communication functions of the products via a specially crafted packet, which may lead to a denial of service (DoS) condition .

Credit: vultures@jpcert.or.jp

Affected SoftwareAffected VersionHow to fix
Mitsubishi Electric Melsec Q-q04udpvcpu Firmware=22031
Mitsubishi Electric Q04UD PVC CPU Firmware
Mitsubishi Electric Q06UDPVCPU Firmware=22031
Mitsubishi Electric Q06UDPVCPU Firmware
Mitsubishielectric Q13udpvcpu Firmware=22031
Mitsubishi Electric Melsec Q-Q13UDPVCPU
Mitsubishi Electric Q26udpvcpu Firmware=22031
Mitsubishi Electric Q26udpvcpu Firmware
Mitsubishielectric Q03udvcpu Firmware=22031
Mitsubishi Electric Q03UDVCPU
Mitsubishielectric Q04udvcpu Firmware=22031
Mitsubishi Electric Q04UDVCPU
Mitsubishi Electric Q13U-DVCpu Firmware=22031
Mitsubishi Electric Q13U-DVCPU
Mitsubishi Electric Melsec Q-Q26UDVCPU Firmware=22031
Mitsubishi Electric Q26UDVCPU
Mitsubishi Electric Melsec Q-Q03UDECPU Firmware=22081
Mitsubishi Electric Melsec Q03UDECPU
Mitsubishi Electric Q04UDEHCPU Firmware=22081
Mitsubishi Electric Melsec Q-04UDEHCPU
Mitsubishi Electric Q06UDEHCPU Firmware=22081
Mitsubishi Electric Melsec Q-Q06UDEHCPU
Mitsubishi Electric Q10UDEHCPU Firmware=22081
Mitsubishi Electric Q10UDEHCPU
Mitsubishielectric Q13udehcpu Firmware=22081
Mitsubishielectric Q13udehcpu
Mitsubishielectric Q20udehcpu Firmware=22081
Mitsubishi Electric Q20UDEHCPU
Mitsubishi Electric Q26UDEHCPU Firmware=22081
Mitsubishi Electric Q26UDEHCPU
Mitsubishi Electric Q50UDEHCPU Firmware=22081
Mitsubishi Electric Q50UDEHCPU
Mitsubishi Electric Melsec Q-Q100UDEHCPU=22081
Mitsubishi Electric Q100UDEHCPU
Mitsubishielectric Melsec Iq-r08sfcpu=22
Mitsubishi Electric Melsec IQ-R08SFCPU
Mitsubishi Electric Melsec Iq-R16SFCpu Firmware=22
Mitsubishi Electric Melsec IQ-R16SFCPU
Mitsubishi Electric Melsec Iq-r32sfcpu=22
Mitsubishi Electric Melsec Iq-r32sfcpu
Mitsubishi Electric Melsec IQ-R120PSFCPU=22
Mitsubishi Electric MELSEC iQ-R120
Mitsubishi Electric Melsec IQ-R04ENCPU Firmware=52
Mitsubishi Electric Melsec Iq-R04ENCpu
Mitsubishi Electric Melsec Iq-r08encpu Firmware=52
Mitsubishi Electric Melsec Iq-r08encpu Firmware
Mitsubishi Electric Melsec IQ-R16ENCpu Firmware=52
Mitsubishi Electric Melsec IQ-R16ENCpu Firmware
Mitsubishielectric Melsec Iq-r32encpu=52
Mitsubishi Electric Melsec IQ-R32
Mitsubishielectric Melsec Iq-r120cpu Firmware=52
Mitsubishi Electric MELSEC iQ-R120
Mitsubishi Electric Melsec Iq-R00CPU Firmware=20
Mitsubishielectric Melsec Iq-r00cpu Firmware
Mitsubishi Electric Melsec Iq-r01cpu Firmware=20
Mitsubishi Electric MELSEC IQ-R01CPU
Mitsubishi Electric Melsec IQ-R02 Firmware=20
Mitsubishi Electric MELSEC IQ-R02CPU
Mitsubishi Electric R08PCPU Firmware
Mitsubishi Electric Melsec IQ-R08
Mitsubishi Electric Melsec IQ-R08PSFCPU Firmware
Mitsubishielectric Melsec Iq-r08psfcpu Firmware
Mitsubishi Electric Melsec Iq-R120PCPU Firmware
Mitsubishi Electric Melsec Iq-R120PCPU Firmware
Mitsubishi Electric Melsec IQ-R120PSFCPU
Mitsubishi Electric Melsec IQ-R120PSFCPU
Mitsubishi Electric Melsec Iq-R16MTCPU
Mitsubishi Electric Melsec Iq-R16MTCPU
Mitsubishi Electric Melsec IQ-R16PCPU Firmware
Mitsubishi Electric Melsec Iq-R16PCPU
Mitsubishi Electric Melsec Iq-R16PSFCpu Firmware
Mitsubishi Electric Melsec Iq-R16PSFCpu Firmware
Mitsubishi Electric Melsec IQ-R32MTCPU Firmware
Mitsubishi Electric Melsec IQ-R32MTCPU Firmware
Mitsubishi Electric Melsec IQ-R32PCPU Firmware
Mitsubishielectric Melsec Iq-r32pcpu Firmware
Mitsubishi Electric Melsec Iq-r32psfcpu Firmware
Mitsubishi Electric Melsec Iq-r32psfcpu Firmware
Mitsubishi Electric Melsec IQ-R64MTCPU Firmware
Mitsubishielectric R64mtcpu
Mitsubishi Electric Melsec L02CPU-P Firmware
Mitsubishi Electric Melsec L02CPU-P Firmware
Mitsubishi Electric Melsec L06CPU-P Firmware
Mitsubishi Electric Melsec L06CPU-P
Mitsubishi Electric Melsec L26CPU-PBT Firmware
Mitsubishi Electric Melsec L26CPU-P
Mitsubishi Electric Melsec L26CPU-PBT Firmware
Mitsubishi Electric Melsec L26CPU-PBT
Mitsubishi Electric Melsec-Q Q170MCPU Firmware
Mitsubishi Electric Melsec-Q Q170MCPU
Mitsubishi Electric Melsec Q-Q170MSCPU-S1 Firmware
Mitsubishi Electric Melsec Q-Q170MSCPU-S1
Mitsubishi Electric Melsec Q-Q172DCPU-S1
Mitsubishi Electric Melsec Q-Q172DCPU-S1
Mitsubishi Electric Q172DSCPU Firmware
Mitsubishi Electric Q172DSCPU Firmware
Mitsubishi Electric Melsec Q-Q173DCPU-S1 Firmware
Mitsubishi Electric Melsec Q-Q173DCPU-S1 Firmware
Mitsubishi Electric Q173DScpu Firmware
Mitsubishi Electric Q173DScpu Firmware
Mitsubishi Electric Melsec Q-QMR-MQ100
Mitsubishielectric Melsec Q-qmr-mq100 Firmware

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2020-5652?

    CVE-2020-5652 is classified with a high severity due to its potential for resource exhaustion which can disrupt services.

  • How do I fix CVE-2020-5652?

    To fix CVE-2020-5652, it is recommended to update the affected CPU firmware to the latest version provided by Mitsubishi Electric.

  • What products are affected by CVE-2020-5652?

    CVE-2020-5652 affects various Mitsubishi Electric MELSEC iQ-R, Q, and L series CPU modules running specified firmware versions.

  • What type of vulnerability is CVE-2020-5652?

    CVE-2020-5652 is classified as an uncontrolled resource consumption vulnerability.

  • When was CVE-2020-5652 disclosed?

    CVE-2020-5652 was disclosed in 2020 as part of Mitsubishi Electric's security advisory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203