ZeroHour

CVE-2021-20591

CVSS 3.1
7.5 high
EPSS
1%p73
Published
()
Modified
Description

Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R00/01/02CPU all versions, R04/08/16/32/120(EN)CPU all versions, R08/16/32/120SFCPU all versions, R08/16/32/120PCPU all versions, R08/16/32/120PSFCPU all versions) allows a remote unauthenticated attacker to prevent legitimate clients from connecting to the MELSOFT transmission port (TCP/IP) by not closing a connection properly, which may lead to a denial of service (DoS) condition.

Vendors
mitsubishielectric
Products
r00cpu firmware, r01cpu firmware, r02cpu firmware, r04cpu firmware, r08cpu firmware, r16cpu firmware, r32cpu firmware, r120cpu firmware, r08sfcpu firmware, r16sfcpu firmware, r32sfcpu firmware, r120sfcpu firmware
Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.