Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-5652

EPSS 2.97% · P87
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2020-5652

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Uncontrolled resource consumption vulnerability in Ethernet Port on MELSEC iQ-R, Q and L series CPU modules (R 00/01/02 CPU firmware versions '20' and earlier, R 04/08/16/32/120 (EN) CPU firmware versions '52' and earlier, R 08/16/32/120 SFCPU firmware versions '22' and earlier, R 08/16/32/120 PCPU all versions, R 08/16/32/120 PSFCPU all versions, R 16/32/64 MTCPU all versions, Q03 UDECPU, Q 04/06/10/13/20/26/50/100 UDEHCPU serial number '22081' and earlier , Q 03/04/06/13/26 UDVCPU serial number '22031' and earlier, Q 04/06/13/26 UDPVCPU serial number '22031' and earlier, Q 172/173 DCPU all versions, Q 172/173 DSCPU all versions, Q 170 MCPU all versions, Q 170 MSCPU all versions, L 02/06/26 CPU (-P) and L 26 CPU - (P) BT all versions) allows a remote unauthenticated attacker to stop the Ethernet communication functions of the products via a specially crafted packet, which may lead to a denial of service (DoS) condition .
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
多款Mitsubishi Electric产品资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mitsubishi Electric MELSEC-Q Series等都是日本三菱电机(Mitsubishi Electric)公司的产品。MELSEC-Q Series是一款MELSEC-Q系列的可编程逻辑控制器。MELSEC-L Series是一款MELSEC-L系列的可编程逻辑控制器。MELSEC iQ-R series是一款可编程逻辑控制器。 MELSEC iQ-R Series 存在资源管理错误漏洞,该漏洞源于当 CPU 模块从恶意攻击者那里接收到一个特制的数据包时,以太网通信可能进入拒绝服务
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Mitsubishi Electric CorporationMELSEC iQ-R, Q and L series R 00/01/02 CPU firmware versions '20' and earlier, R 04/08/16/32/120 (EN) CPU firmware versions '52' and earlier, R 08/16/32/120 SFCPU firmware versions '22' and earlier, R 08/16/32/120 PCPU all versions, R 08/16/32/120 PSFCPU all versions, R 16/32/64 MTC -

II. Public POCs for CVE-2020-5652

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-5652

Please Login to view more intelligence information

Same Patch Batch · Mitsubishi Electric Corporation · 2020-10-30 · 7 CVEs total

CVE-2020-5657多款Mitsubishi Electric产品参数注入漏洞
CVE-2020-5658多款Mitsubishi Electric产品资源管理错误漏洞
CVE-2020-5655多款Mitsubishi Electric产品代码问题漏洞
CVE-2020-5656多款Mitsubishi Electric产品安全漏洞
CVE-2020-5653多款Mitsubishi Electric产品安全漏洞
CVE-2020-5654多款Mitsubishi Electric产品授权问题漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2020-5652

No comments yet


Leave a comment