NULL Pointer Dereference in MELSEC iQ-R Series Products by Mitsubishi Electric
CVE-2020-5655

7.5HIGH

Key Information:

Vendor
CVE Published:
2 November 2020

Summary

The NULL pointer dereference vulnerability in the TCP/IP function of the MELSEC iQ-R series firmware could allow a remote, unauthenticated attacker to disrupt the network operations of affected products. By sending specially crafted packets, the attacker can exploit this vulnerability to incapacitate critical network functions, posing a significant risk to system integrity and performance. Organizations utilizing these products should review their firmware versions and implement necessary measures to safeguard their systems.

Affected Version(s)

MELSEC iQ-R series RJ71EIP91 EtherNet/IP Network Interface Module First 2 digits of serial number are '02' or before, RJ71PN92 PROFINET IO Controller Module First 2 digits of serial number are '01' or before, RD81DL96 High Speed Data Logger Module First 2 digits of serial number are '08' or before, RD81MES96N MES Interface Module First 2 digits of serial number are '04' or before, and RD81OPC96 OPC UA Server Module First 2 digits of serial number are '04' or before

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.