ZeroHour

CVE-2020-5666

CVSS 3.1
7.5 high
EPSS
9%p95
Published
()
Modified
Description

Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '05' to '19' and R04/08/16/32/120(EN)CPU Firmware versions from '35' to '51') allows a remote attacker to cause an error in a CPU unit via a specially crafted HTTP packet, which may lead to a denial-of-service (DoS) condition in execution of the program and its communication.

Vendors
mitsubishielectric
Products
melsec iq-r00 firmware, melsec iq-r01 firmware, melsec iq-r02 firmware, melsec iq-r04 firmware, melsec iq-r16 firmware, melsec iq-r08 firmware, melsec iq-r32 firmware, melsec iq-r120 firmware
Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.