7.8
CVSSv2

CVE-2020-13238

Published: 10/06/2020 Updated: 23/06/2020
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Mitsubishi MELSEC iQ-R Series PLCs with firmware 33 allow malicious users to halt the industrial process by sending an unauthenticated crafted packet over the network, because this denial of service attack consumes excessive CPU time. After halting, physical access to the PLC is required in order to restore production.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mitsubishielectric melsec_iq-r00cpu_firmware

mitsubishielectric melsec_iq-r01cpu_firmware

mitsubishielectric melsec_iq-r02cpu_firmware

mitsubishielectric melsec_iq-r04cpu_firmware

mitsubishielectric melsec_iq-r08cpu_firmware

mitsubishielectric melsec_iq-r16cpu_firmware

mitsubishielectric melsec_iq-r32cpu_firmware

mitsubishielectric melsec_iq-r120cpu_firmware

mitsubishielectric melsec_iq-r08fcpu_firmware

mitsubishielectric melsec_iq-r16fcpu_firmware

mitsubishielectric melsec_iq-r32fcpu_firmware

mitsubishielectric melsec_iq-r120fcpu_firmware

mitsubishielectric melsec_iq-r08pcpu_firmware

mitsubishielectric melsec_iq-r16pcpu_firmware

mitsubishielectric melsec_iq-r32pcpu_firmware

mitsubishielectric melsec_iq-r120pcpu_firmware

mitsubishielectric melsec_iq-r08sfcpu_firmware

mitsubishielectric melsec_iq-r16sfcpu_firmware

mitsubishielectric melsec_iq-r32sfcpu_firmware

mitsubishielectric melsec_iq-r120sfcpu_firmware

mitsubishielectric melsec_iq-rj71en71_firmware

Github Repositories

blogs, CVEs, and other publications

Publications Here are some of my blogs, CVEs, and other publications CVEs: CVE-2021-30186: CWE-122: Heap-based Buffer Overflow CVE-2020-13238: CWE-400 Uncontrolled Resource Consumption CVE-2020-16850: CWE-400 Uncontrolled Resource Consumption CVE-2020-24685: CWE-789 Memory Allocation with Excessive Size Value Blog Posts: OpenSSL Vulnerability - What It Means For Your