First published: Mon Nov 02 2020(Updated: )
Uncontrolled resource consumption vulnerability in Ethernet Port on MELSEC iQ-R, Q and L series CPU modules (R 00/01/02 CPU firmware versions '20' and earlier, R 04/08/16/32/120 (EN) CPU firmware versions '52' and earlier, R 08/16/32/120 SFCPU firmware versions '22' and earlier, R 08/16/32/120 PCPU all versions, R 08/16/32/120 PSFCPU all versions, R 16/32/64 MTCPU all versions, Q03 UDECPU, Q 04/06/10/13/20/26/50/100 UDEHCPU serial number '22081' and earlier , Q 03/04/06/13/26 UDVCPU serial number '22031' and earlier, Q 04/06/13/26 UDPVCPU serial number '22031' and earlier, Q 172/173 DCPU all versions, Q 172/173 DSCPU all versions, Q 170 MCPU all versions, Q 170 MSCPU all versions, L 02/06/26 CPU (-P) and L 26 CPU - (P) BT all versions) allows a remote unauthenticated attacker to stop the Ethernet communication functions of the products via a specially crafted packet, which may lead to a denial of service (DoS) condition .
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishi Electric Melsec Q-q04udpvcpu Firmware | =22031 | |
Mitsubishi Electric Q04UD PVC CPU Firmware | ||
Mitsubishi Electric Q06UDPVCPU Firmware | =22031 | |
Mitsubishi Electric Q06UDPVCPU Firmware | ||
Mitsubishielectric Q13udpvcpu Firmware | =22031 | |
Mitsubishi Electric Melsec Q-Q13UDPVCPU | ||
Mitsubishi Electric Q26udpvcpu Firmware | =22031 | |
Mitsubishi Electric Q26udpvcpu Firmware | ||
Mitsubishielectric Q03udvcpu Firmware | =22031 | |
Mitsubishi Electric Q03UDVCPU | ||
Mitsubishielectric Q04udvcpu Firmware | =22031 | |
Mitsubishi Electric Q04UDVCPU | ||
Mitsubishi Electric Q13U-DVCpu Firmware | =22031 | |
Mitsubishi Electric Q13U-DVCPU | ||
Mitsubishi Electric Melsec Q-Q26UDVCPU Firmware | =22031 | |
Mitsubishi Electric Q26UDVCPU | ||
Mitsubishi Electric Melsec Q-Q03UDECPU Firmware | =22081 | |
Mitsubishi Electric Melsec Q03UDECPU | ||
Mitsubishi Electric Q04UDEHCPU Firmware | =22081 | |
Mitsubishi Electric Melsec Q-04UDEHCPU | ||
Mitsubishi Electric Q06UDEHCPU Firmware | =22081 | |
Mitsubishi Electric Melsec Q-Q06UDEHCPU | ||
Mitsubishi Electric Q10UDEHCPU Firmware | =22081 | |
Mitsubishi Electric Q10UDEHCPU | ||
Mitsubishielectric Q13udehcpu Firmware | =22081 | |
Mitsubishielectric Q13udehcpu | ||
Mitsubishielectric Q20udehcpu Firmware | =22081 | |
Mitsubishi Electric Q20UDEHCPU | ||
Mitsubishi Electric Q26UDEHCPU Firmware | =22081 | |
Mitsubishi Electric Q26UDEHCPU | ||
Mitsubishi Electric Q50UDEHCPU Firmware | =22081 | |
Mitsubishi Electric Q50UDEHCPU | ||
Mitsubishi Electric Melsec Q-Q100UDEHCPU | =22081 | |
Mitsubishi Electric Q100UDEHCPU | ||
Mitsubishielectric Melsec Iq-r08sfcpu | =22 | |
Mitsubishi Electric Melsec IQ-R08SFCPU | ||
Mitsubishi Electric Melsec Iq-R16SFCpu Firmware | =22 | |
Mitsubishi Electric Melsec IQ-R16SFCPU | ||
Mitsubishi Electric Melsec Iq-r32sfcpu | =22 | |
Mitsubishi Electric Melsec Iq-r32sfcpu | ||
Mitsubishi Electric Melsec IQ-R120PSFCPU | =22 | |
Mitsubishi Electric MELSEC iQ-R120 | ||
Mitsubishi Electric Melsec IQ-R04ENCPU Firmware | =52 | |
Mitsubishi Electric Melsec Iq-R04ENCpu | ||
Mitsubishi Electric Melsec Iq-r08encpu Firmware | =52 | |
Mitsubishi Electric Melsec Iq-r08encpu Firmware | ||
Mitsubishi Electric Melsec IQ-R16ENCpu Firmware | =52 | |
Mitsubishi Electric Melsec IQ-R16ENCpu Firmware | ||
Mitsubishielectric Melsec Iq-r32encpu | =52 | |
Mitsubishi Electric Melsec IQ-R32 | ||
Mitsubishielectric Melsec Iq-r120cpu Firmware | =52 | |
Mitsubishi Electric MELSEC iQ-R120 | ||
Mitsubishi Electric Melsec Iq-R00CPU Firmware | =20 | |
Mitsubishielectric Melsec Iq-r00cpu Firmware | ||
Mitsubishi Electric Melsec Iq-r01cpu Firmware | =20 | |
Mitsubishi Electric MELSEC IQ-R01CPU | ||
Mitsubishi Electric Melsec IQ-R02 Firmware | =20 | |
Mitsubishi Electric MELSEC IQ-R02CPU | ||
Mitsubishi Electric R08PCPU Firmware | ||
Mitsubishi Electric Melsec IQ-R08 | ||
Mitsubishi Electric Melsec IQ-R08PSFCPU Firmware | ||
Mitsubishielectric Melsec Iq-r08psfcpu Firmware | ||
Mitsubishi Electric Melsec Iq-R120PCPU Firmware | ||
Mitsubishi Electric Melsec Iq-R120PCPU Firmware | ||
Mitsubishi Electric Melsec IQ-R120PSFCPU | ||
Mitsubishi Electric Melsec IQ-R120PSFCPU | ||
Mitsubishi Electric Melsec Iq-R16MTCPU | ||
Mitsubishi Electric Melsec Iq-R16MTCPU | ||
Mitsubishi Electric Melsec IQ-R16PCPU Firmware | ||
Mitsubishi Electric Melsec Iq-R16PCPU | ||
Mitsubishi Electric Melsec Iq-R16PSFCpu Firmware | ||
Mitsubishi Electric Melsec Iq-R16PSFCpu Firmware | ||
Mitsubishi Electric Melsec IQ-R32MTCPU Firmware | ||
Mitsubishi Electric Melsec IQ-R32MTCPU Firmware | ||
Mitsubishi Electric Melsec IQ-R32PCPU Firmware | ||
Mitsubishielectric Melsec Iq-r32pcpu Firmware | ||
Mitsubishi Electric Melsec Iq-r32psfcpu Firmware | ||
Mitsubishi Electric Melsec Iq-r32psfcpu Firmware | ||
Mitsubishi Electric Melsec IQ-R64MTCPU Firmware | ||
Mitsubishielectric R64mtcpu | ||
Mitsubishi Electric Melsec L02CPU-P Firmware | ||
Mitsubishi Electric Melsec L02CPU-P Firmware | ||
Mitsubishi Electric Melsec L06CPU-P Firmware | ||
Mitsubishi Electric Melsec L06CPU-P | ||
Mitsubishi Electric Melsec L26CPU-PBT Firmware | ||
Mitsubishi Electric Melsec L26CPU-P | ||
Mitsubishi Electric Melsec L26CPU-PBT Firmware | ||
Mitsubishi Electric Melsec L26CPU-PBT | ||
Mitsubishi Electric Melsec-Q Q170MCPU Firmware | ||
Mitsubishi Electric Melsec-Q Q170MCPU | ||
Mitsubishi Electric Melsec Q-Q170MSCPU-S1 Firmware | ||
Mitsubishi Electric Melsec Q-Q170MSCPU-S1 | ||
Mitsubishi Electric Melsec Q-Q172DCPU-S1 | ||
Mitsubishi Electric Melsec Q-Q172DCPU-S1 | ||
Mitsubishi Electric Q172DSCPU Firmware | ||
Mitsubishi Electric Q172DSCPU Firmware | ||
Mitsubishi Electric Melsec Q-Q173DCPU-S1 Firmware | ||
Mitsubishi Electric Melsec Q-Q173DCPU-S1 Firmware | ||
Mitsubishi Electric Q173DScpu Firmware | ||
Mitsubishi Electric Q173DScpu Firmware | ||
Mitsubishi Electric Melsec Q-QMR-MQ100 | ||
Mitsubishielectric Melsec Q-qmr-mq100 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5652 is classified with a high severity due to its potential for resource exhaustion which can disrupt services.
To fix CVE-2020-5652, it is recommended to update the affected CPU firmware to the latest version provided by Mitsubishi Electric.
CVE-2020-5652 affects various Mitsubishi Electric MELSEC iQ-R, Q, and L series CPU modules running specified firmware versions.
CVE-2020-5652 is classified as an uncontrolled resource consumption vulnerability.
CVE-2020-5652 was disclosed in 2020 as part of Mitsubishi Electric's security advisory.