7.8
CVSSv2

CVE-2020-16850

Published: 30/11/2020 Updated: 21/07/2021
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated malicious user to halt the industrial process by sending a crafted packet over the network. This denial of service attack exposes Improper Input Validation. After halting, physical access to the PLC is required in order to restore production, and the device state is lost. This is related to R04CPU, RJ71GF11-T2, R04CPU, and RJ71GF11-T2.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mitsubishielectric r00cpu_firmware

mitsubishielectric r01cpu_firmware

mitsubishielectric r02cpu_firmware

mitsubishielectric r04cpu_firmware

mitsubishielectric r08cpu_firmware

mitsubishielectric r16cpu_firmware

mitsubishielectric r32cpu_firmware

mitsubishielectric r120cpu_firmware

mitsubishielectric r08sfcpu_firmware

mitsubishielectric r16sfcpu_firmware

mitsubishielectric r32sfcpu_firmware

mitsubishielectric r120sfcpu_firmware

mitsubishielectric r08pcpu_firmware

mitsubishielectric r16pcpu_firmware

mitsubishielectric r32pcpu_firmware

mitsubishielectric r120pcpu_firmware

mitsubishielectric r16mtcpu_firmware

mitsubishielectric r32mtcpu_firmware

mitsubishielectric r64mtcpu_firmware

Github Repositories

blogs, CVEs, and other publications

Publications Here are some of my blogs, CVEs, and other publications CVEs: CVE-2021-30186: CWE-122: Heap-based Buffer Overflow CVE-2020-13238: CWE-400 Uncontrolled Resource Consumption CVE-2020-16850: CWE-400 Uncontrolled Resource Consumption CVE-2020-24685: CWE-789 Memory Allocation with Excessive Size Value Blog Posts: OpenSSL Vulnerability - What It Means For Your