7.5
CVSSv3

CVE-2020-13238

Published: 10/06/2020 Updated: 23/06/2020
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Mitsubishi MELSEC iQ-R Series PLCs with firmware 33 allow malicious users to halt the industrial process by sending an unauthenticated crafted packet over the network, because this denial of service attack consumes excessive CPU time. After halting, physical access to the PLC is required in order to restore production.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mitsubishielectric melsec iq-r00cpu firmware

mitsubishielectric melsec iq-r01cpu firmware

mitsubishielectric melsec iq-r02cpu firmware

mitsubishielectric melsec iq-r04cpu firmware

mitsubishielectric melsec iq-r08cpu firmware

mitsubishielectric melsec iq-r16cpu firmware

mitsubishielectric melsec iq-r32cpu firmware

mitsubishielectric melsec iq-r120cpu firmware

mitsubishielectric melsec iq-r08fcpu firmware

mitsubishielectric melsec iq-r16fcpu firmware

mitsubishielectric melsec iq-r32fcpu firmware

mitsubishielectric melsec iq-r120fcpu firmware

mitsubishielectric melsec iq-r08pcpu firmware

mitsubishielectric melsec iq-r16pcpu firmware

mitsubishielectric melsec iq-r32pcpu firmware

mitsubishielectric melsec iq-r120pcpu firmware

mitsubishielectric melsec iq-r08sfcpu firmware

mitsubishielectric melsec iq-r16sfcpu firmware

mitsubishielectric melsec iq-r32sfcpu firmware

mitsubishielectric melsec iq-r120sfcpu firmware

mitsubishielectric melsec iq-rj71en71 firmware

Github Repositories

blogs, CVEs, and other publications

Publications Here are some of my blogs, CVEs, and other publications CVEs: CVE-2021-30186: CWE-122: Heap-based Buffer Overflow CVE-2020-13238: CWE-400 Uncontrolled Resource Consumption CVE-2020-16850: CWE-400 Uncontrolled Resource Consumption CVE-2020-24685: CWE-789 Memory Allocation with Excessive Size Value Blog Posts: OpenSSL Vulnerability - What It Means For Your