CVE-2020-5527

CVSS V2 Medium 5 CVSS V3 High 7.5
Description
When MELSOFT transmission port (UDP/IP) of Mitsubishi Electric MELSEC iQ-R series (all versions), MELSEC iQ-F series (all versions), MELSEC Q series (all versions), MELSEC L series (all versions), and MELSEC F series (all versions) receives massive amount of data via unspecified vectors, resource consumption occurs and the port does not process the data properly. As a result, it may fall into a denial-of-service (DoS) condition. The vendor states this vulnerability only affects Ethernet communication functions.
Overview
  • CVE ID
  • CVE-2020-5527
  • Assigner
  • vultures@jpcert.or.jp
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2020-03-30T08:15:17
  • Last Modified Date
  • 2020-04-07T13:49:38
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:o:mitsubishielectric:cr800-q_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:cr800-q:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:fx3g_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:fx3g:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:fx3gc_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:fx3gc:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:fx3s_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:fx3s:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:fx3u_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:fx3u:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:fx3uc_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:fx3uc:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:fx5u_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:fx5u:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:fx5uc_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:fx5uc:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:fx5uj_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:fx5uj:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l02cpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l02cpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l02cpu-p_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l02cpu-p:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l02scpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l02scpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l02scpu-p_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l02scpu-p:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l06cpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l06cpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l06cpu-p_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l06cpu-p:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l26cpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l26cpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l26cpu-bt_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l26cpu-bt:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l26cpu-p_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l26cpu-p:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:l26cpu-pbt_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:l26cpu-pbt:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q02phcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q02phcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q06phcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q06phcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q12dccpu-v_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q12dccpu-v:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q12phcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q12phcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q12prhcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q12prhcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q172dscpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q172dscpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q173dscpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q173dscpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q173nccpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q173nccpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q24dhccpu-ls_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q24dhccpu-ls:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q24dhccpu-v_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q24dhccpu-v:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q24dhccpu-vg2_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q24dhccpu-vg2:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q25phcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q25phcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q25prhcpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q25prhcpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:q26dhccpu-ls_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:q26dhccpu-ls:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:r00cpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:r00cpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:r01cpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:r01cpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:r02cpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:r02cpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:r04cpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:r04cpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:r04encpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:r04encpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:r08cpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:r08cpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:r08encpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:r08encpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:r120cpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:r120cpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:r120encpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:r120encpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:r16cpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:r16cpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:r16encpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:r16encpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:r32cpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:r32cpu:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:mitsubishielectric:r32encpu_firmware:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:mitsubishielectric:r32encpu:-:*:*:*:*:*:*:* 0 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:L/Au:N/C:N/I:N/A:P
  • Access Vector
  • NETWORK
  • Access Compatibility
  • LOW
  • Authentication
  • NONE
  • Confidentiality Impact
  • NONE
  • Integrity Impact
  • NONE
  • Availability Impact
  • PARTIAL
  • Base Score
  • 5
  • Severity
  • MEDIUM
  • Exploitability Score
  • 10
  • Impact Score
  • 2.9
CVSS Version 3
  • Version
  • 3.1
  • Vector String
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • NONE
  • User Interaction
  • NONE
  • Scope
  • UNCHANGED
  • Confidentiality Impact
  • NONE
  • Availability Impact
  • HIGH
  • Base Score
  • 7.5
  • Base Severity
  • HIGH
  • Exploitability Score
  • 3.9
  • Impact Score
  • 3.6
History
Created Old Value New Value Data Type Notes
2022-05-10 16:45:23 Added to TrackCVE
2022-12-04 13:40:58 2020-03-30T08:15Z 2020-03-30T08:15:17 CVE Published Date updated
2022-12-04 13:40:58 2020-04-07T13:49:38 CVE Modified Date updated
2022-12-04 13:40:58 Analyzed Vulnerability Status updated