CVE-2020-5527
Severity CVSS v4.0:
Pending analysis
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
30/03/2020
Last modified:
07/04/2020
Description
When MELSOFT transmission port (UDP/IP) of Mitsubishi Electric MELSEC iQ-R series (all versions), MELSEC iQ-F series (all versions), MELSEC Q series (all versions), MELSEC L series (all versions), and MELSEC F series (all versions) receives massive amount of data via unspecified vectors, resource consumption occurs and the port does not process the data properly. As a result, it may fall into a denial-of-service (DoS) condition. The vendor states this vulnerability only affects Ethernet communication functions.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:mitsubishielectric:cr800-q_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mitsubishielectric:cr800-q:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:fx3g_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mitsubishielectric:fx3g:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:fx3gc_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mitsubishielectric:fx3gc:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:fx3s_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mitsubishielectric:fx3s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:fx3u_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mitsubishielectric:fx3u:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:fx3uc_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mitsubishielectric:fx3uc:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:fx5u_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mitsubishielectric:fx5u:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:fx5uc_firmware:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



