CVE-2021-20612
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/01/2022
Last modified:
08/08/2023
Description
Lack of administrator control over security vulnerability in MELSEC-F series FX3U-ENET Firmware version 1.14 and prior, FX3U-ENET-L Firmware version 1.14 and prior and FX3U-ENET-P502 Firmware version 1.14 and prior allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition in communication function of the product or other unspecified effects by sending specially crafted packets to an unnecessary opening of TCP port. Control by MELSEC-F series PLC is not affected by this vulnerability, but system reset is required for recovery.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:mitsubishielectric:fx3u-enet_firmware:*:*:*:*:*:*:*:* | 1.14 (including) | |
| cpe:2.3:h:mitsubishielectric:fx3u-enet:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:fx3u-enet-l_firmware:*:*:*:*:*:*:*:* | 1.14 (including) | |
| cpe:2.3:h:mitsubishielectric:fx3u-enet-l:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:fx3u-enet-p502_firmware:*:*:*:*:*:*:*:* | 1.14 (including) | |
| cpe:2.3:h:mitsubishielectric:fx3u-enet-p502:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



