CVE-2021-20596: Null Pointer Dereference
NULL Pointer Dereference in MELSEC-F Series FX3U-ENET firmware version 1.14 and prior, FX3U-ENET-L firmware version 1.14 and prior and FX3U-ENET-P502 firmware version 1.14 and prior allows a remote unauthenticated attacker to cause a DoS condition in communication by sending specially crafted packets. Control by MELSEC-F series PLC is not affected and system reset is required for recovery.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-20596?
CVE-2021-20596 is a vulnerability that allows a remote unauthenticated attacker to cause a Denial of Service (DoS) condition in communication by sending a specially crafted packet.
How does CVE-2021-20596 impact the affected software?
CVE-2021-20596 impacts MELSEC-F Series FX3U-ENET firmware versions 1.14 and prior, FX3U-ENET-L firmware versions 1.14 and prior, and FX3U-ENET-P502 firmware versions 1.14 and prior.
What is the severity of CVE-2021-20596?
CVE-2021-20596 has a severity rating of 7.5 (High).
How can I fix CVE-2021-20596?
To fix CVE-2021-20596, users should update the affected software to a version that is not vulnerable.
Where can I find more information about CVE-2021-20596?
More information about CVE-2021-20596 can be found at the following references: [JVN](https://jvn.jp/vu/JVNVU94348759/index.html), [US-CERT](https://us-cert.cisa.gov/ics/advisories/icsa-21-201-01), [Mitsubishi Electric PSIRT](https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-006_en.pdf).