CVE-2021-20613: High severity mitsubishi electric fx3u-enet vulnerability
Improper initialization vulnerability in MELSEC-F series FX3U-ENET Firmware version 1.16 and prior, FX3U-ENET-L Firmware version 1.16 and prior and FX3U-ENET-P502 Firmware version 1.16 and prior allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition in communication function of the product by sending specially crafted packets. Control by MELSEC-F series PLC is not affected by this vulnerability, but system reset is required for recovery.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-20613.
What is the severity of CVE-2021-20613?
The severity of CVE-2021-20613 is high with a CVSS score of 7.5.
Which software versions are affected by CVE-2021-20613?
CVE-2021-20613 affects MELSEC-F series FX3U-ENET Firmware version 1.16 and prior, FX3U-ENET-L Firmware version 1.16 and prior, and FX3U-ENET-P502 Firmware version 1.16 and prior.
How can an attacker exploit CVE-2021-20613?
An attacker can exploit CVE-2021-20613 by sending specially crafted packets to the affected device, causing a denial-of-service (DoS) condition in communication functions.
Are there any fixes available for CVE-2021-20613?
Yes, Mitsubishi Electric has released a firmware update to address the vulnerability. Please refer to the vendor's advisory for more information.