CVE-2021-20591
moderate-risk
Published 2021-06-11
Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R00/01/02CPU all versions, R04/08/16/32/120(EN)CPU all versions, R08/16/32/120SFCPU all versions, R08/16/32/120PCPU all versions, R08/16/32/120PSFCPU all versions) allows a remote unauthenticated attacker to prevent legitimate clients from connecting to the MELSOFT transmission port (TCP/IP) by not closing a connection properly, which may lead to a denial of service (DoS) condition.
Do I need to act?
-
0.50% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
Affected Products (20)
R00Cpu Firmware
R01Cpu Firmware
R02Cpu Firmware
R04Cpu Firmware
R08Cpu Firmware
R16Cpu Firmware
R32Cpu Firmware
R120Cpu Firmware
R08Sfcpu Firmware
R16Sfcpu Firmware
R32Sfcpu Firmware
R120Sfcpu Firmware
R08Pcpu Firmware
R16Pcpu Firmware
R32Pcpu Firmware
R120Pcpu Firmware
R08Psfcpu Firmware
R16Psfcpu Firmware
R32Psfcpu Firmware
R120Psfcpu Firmware
Affected Vendors
References (4)
Third Party Advisory
https://jvn.jp/vu/JVNVU98060539/index.html
Third Party Advisory
https://jvn.jp/vu/JVNVU98060539/index.html
48
/ 100
moderate-risk
Severity
26/34 · High
Exploitability
2/34 · Minimal
Exposure
20/34 · Moderate