NULL Pointer Dereference in MELSEC iQ-R Series Products by Mitsubishi Electric
CVE-2020-5655
Key Information:
- Status
- Vendor
- CVE Published:
- 2 November 2020
Summary
The NULL pointer dereference vulnerability in the TCP/IP function of the MELSEC iQ-R series firmware could allow a remote, unauthenticated attacker to disrupt the network operations of affected products. By sending specially crafted packets, the attacker can exploit this vulnerability to incapacitate critical network functions, posing a significant risk to system integrity and performance. Organizations utilizing these products should review their firmware versions and implement necessary measures to safeguard their systems.
Affected Version(s)
MELSEC iQ-R series RJ71EIP91 EtherNet/IP Network Interface Module First 2 digits of serial number are '02' or before, RJ71PN92 PROFINET IO Controller Module First 2 digits of serial number are '01' or before, RD81DL96 High Speed Data Logger Module First 2 digits of serial number are '08' or before, RD81MES96N MES Interface Module First 2 digits of serial number are '04' or before, and RD81OPC96 OPC UA Server Module First 2 digits of serial number are '04' or before
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved