CVE-2021-20591: High severity mitsubishi electric r00cpu firmware vulnerability
Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R00/01/02CPU all versions, R04/08/16/32/120(EN)CPU all versions, R08/16/32/120SFCPU all versions, R08/16/32/120PCPU all versions, R08/16/32/120PSFCPU all versions) allows a remote unauthenticated attacker to prevent legitimate clients from connecting to the MELSOFT transmission port (TCP/IP) by not closing a connection properly, which may lead to a denial of service (DoS) condition.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-20591?
CVE-2021-20591 is a vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules that allows a remote unauthenticated attacker to cause uncontrolled resource consumption.
What is the severity of CVE-2021-20591?
The severity of CVE-2021-20591 is high with a CVSS score of 7.5.
Which software versions are affected by CVE-2021-20591?
The vulnerability affects all versions of Mitsubishi Electric MELSEC iQ-R series CPU modules, including R00/01/02CPU, R04/08/16/32/120(EN)CPU, R08/16/32/120SFCPU, R08/16/32/120PCPU, and R08/16/32/120PSFCPU.
How can an attacker exploit CVE-2021-20591?
An attacker can exploit CVE-2021-20591 remotely and without authentication to cause uncontrolled resource consumption.
Are there any fixes or patches available for CVE-2021-20591?
Yes, Mitsubishi Electric has released a patch to address the vulnerability. Please refer to the official advisory for further instructions.