Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2021-20611

Quick assessment

Affected
Mitsubishi Electric Corporation MELSEC iQ-R Series R00CPU
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Mitsubishi Electric MELSEC iQ-R series是日本三菱电机(Mitsubishi Electric)公司的一款可编程逻辑控制器。 Mitsubishi Electric MELSEC iQ-R series 存在输入验证错误漏洞,该漏洞源于没有正确控制有限资源的分配和维护,从而使行为者能够影响消耗的资源量,最终导致可用资源枯竭。以下产品和版本受到影响:MELSEC iQ-R series,Mitsubishi Electric MELSEC Q series,MELSEC-

CVSS 7.5 · High EPSS 3.18% · P88

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-20611

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, MELSEC iQ-R Series R08/16/32/120PCPU, MELSEC iQ-R Series R08/16/32/120PSFCPU, MELSEC iQ-R Series R16/32/64MTCPU, MELSEC iQ-R Series R12CCPU-V, MELSEC Q Series Q03UDECPU, MELSEC Q Series Q04/06/10/13/20/26/50/100UDEHCPU, MELSEC Q Series Q03/04/06/13/26UDVCPU, MELSEC Q Series Q04/06/13/26UDPVCPU, MELSEC Q Series Q12DCCPU-V, MELSEC Q Series Q24DHCCPU-V(G), MELSEC Q Series Q24/26DHCCPU-LS, MELSEC Q Series MR-MQ100, MELSEC Q Series Q172/173DCPU-S1, MELSEC Q Series Q172/173DSCPU, MELSEC Q Series Q170MCPU, MELSEC Q Series Q170MSCPU(-S1), MELSEC L Series L02/06/26CPU(-P), MELSEC L Series L26CPU-(P)BT and MELIPC Series MI5122-VW allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by sending specially crafted packets. System reset is required for recovery.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
Mitsubishi Electric MELSEC iQ-R series 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mitsubishi Electric MELSEC iQ-R series是日本三菱电机(Mitsubishi Electric)公司的一款可编程逻辑控制器。 Mitsubishi Electric MELSEC iQ-R series 存在输入验证错误漏洞,该漏洞源于没有正确控制有限资源的分配和维护,从而使行为者能够影响消耗的资源量,最终导致可用资源枯竭。以下产品和版本受到影响:MELSEC iQ-R series,Mitsubishi Electric MELSEC Q series,MELSEC-
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Mitsubishi Electric Corporation MELSEC iQ-R Series R00CPU Firmware versions "24" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R01CPU Firmware versions "24" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R02CPU Firmware versions "24" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R04CPU Firmware versions "57" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R08CPU Firmware versions "57" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R16CPU Firmware versions "57" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R32CPU Firmware versions "57" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R120CPU Firmware versions "57" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R04ENCPU Firmware versions "57" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R08ENCPU Firmware versions "57" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R16ENCPU Firmware versions "57" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R32ENCPU Firmware versions "57" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R120ENCPU Firmware versions "57" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R08SFCPU Firmware versions "26" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R16SFCPU Firmware versions "26" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R32SFCPU Firmware versions "26" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R120SFCPU Firmware versions "26" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R08PCPU Firmware versions "29" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R16PCPU Firmware versions "29" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R32PCPU Firmware versions "29" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R120PCPU Firmware versions "29" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R08PSFCPU Firmware versions "08" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R16PSFCPU Firmware versions "08" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R32PSFCPU Firmware versions "08" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R120PSFCPU Firmware versions "08" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R16MTCPU Operating system software version "23" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R32MTCPU Operating system software version "23" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R64MTCPU Operating system software version "23" and prior -
Mitsubishi Electric Corporation MELSEC iQ-R Series R12CCPU-V Firmware versions "16" and prior -
Mitsubishi Electric Corporation MELSEC Q Series Q03UDECPU The first 5 digits of serial No. "23121" and prior -

II. Public POCs for CVE-2021-20611

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-20611

请登录查看更多情报信息。

Vendor Advisories for CVE-2021-20611 (2)

Same Patch Batch · Mitsubishi Electric Corporation · 2021-12-01 · 3 CVEs total

CVE-2021-20610 7.5 HIGH 多款Mitsubishi Electric产品安全漏洞
CVE-2021-20609 7.5 HIGH Mitsubishi Electric MELSEC Q series 资源管理错误漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2021-20611

No comments yet


Leave a comment