CVE-2021-20610

high-risk
Published 2021-12-01

Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, MELSEC iQ-R Series R08/16/32/120PCPU, MELSEC iQ-R Series R08/16/32/120PSFCPU, MELSEC iQ-R Series R16/32/64MTCPU, MELSEC iQ-R Series R12CCPU-V, MELSEC Q Series Q03UDECPU, MELSEC Q Series Q04/06/10/13/20/26/50/100UDEHCPU, MELSEC Q Series Q03/04/06/13/26UDVCPU, MELSEC Q Series Q04/06/13/26UDPVCPU, MELSEC Q Series Q12DCCPU-V, MELSEC Q Series Q24DHCCPU-V(G), MELSEC Q Series Q24/26DHCCPU-LS, MELSEC Q Series MR-MQ100, MELSEC Q Series Q172/173DCPU-S1, MELSEC Q Series Q172/173DSCPU, MELSEC Q Series Q170MCPU, MELSEC Q Series Q170MSCPU(-S1), MELSEC L Series L02/06/26CPU(-P), MELSEC L Series L26CPU-(P)BT and MELIPC Series MI5122-VW allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by sending specially crafted packets. System reset is required for recovery.

Do I need to act?

-
0.66% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10 High
NETWORK / LOW complexity

Affected Products (20)

Melsec Iq-R R00 Cpu Firmware
Melsec Iq-R R01 Cpu Firmware
Melsec Iq-R R02 Cpu Firmware
Melsec Iq-R R04 Cpu Firmware
Melsec Iq-R R08 Cpu Firmware
Melsec Iq-R R120 Cpu Firmware
Melsec Iq-R R16 Cpu Firmware
Melsec Iq-R R32 Cpu Firmware
Melsec Iq-R R04 Pcpu Firmware
Melsec Iq-R R08 Pcpu Firmware
Melsec Iq-R R16 Pcpu Firmware
Melsec Iq-R R32 Pcpu Firmware
Melsec Iq-R R120 Pcpu Firmware
Melsec Iq-R R08 Sfcpu Firmware
Melsec Iq-R R16 Sfcpu Firmware
Melsec Iq-R R32 Sfcpu Firmware
Melsec Iq-R R120 Sfcpu Firmware
Melsec Iq-R R16 Mtcpu Firmware
Melsec Iq-R R32 Mtcpu Firmware
Melsec Iq-R R64 Mtcpu Firmware

Affected Vendors

54
/ 100
high-risk
Severity 26/34 · High
Exploitability 2/34 · Minimal
Exposure 26/34 · High