CVE-2021-20591

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
11/06/2021
Last modified:
22/06/2021

Description

Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R00/01/02CPU all versions, R04/08/16/32/120(EN)CPU all versions, R08/16/32/120SFCPU all versions, R08/16/32/120PCPU all versions, R08/16/32/120PSFCPU all versions) allows a remote unauthenticated attacker to prevent legitimate clients from connecting to the MELSOFT transmission port (TCP/IP) by not closing a connection properly, which may lead to a denial of service (DoS) condition.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:mitsubishielectric:r00cpu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:r00cpu:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:r01cpu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:r01cpu:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:r02cpu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:r02cpu:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:r04cpu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:r04cpu:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:r08cpu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:r08cpu:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:r16cpu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:r16cpu:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:r32cpu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:r32cpu:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:r120cpu_firmware:*:*:*:*:*:*:*:*