CVE Feed

    Dashboard / CVE / CVE-2020-5657

    CVE-2020-5657

    Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network Interface Module First 2 digits of serial number are '02' or before, RJ71PN92 PROFINET IO Controller Module First 2 digits of serial number are '01' or before, RD81DL96 High Speed Data Logger Module First 2 digits of serial number are '08' or before, RD81MES96N MES Interface Module First 2 digits of serial number are '04' or before, and RD81OPC96 OPC UA Server Module First 2 digits of serial number are '04' or before) allows unauthenticated attackers on adjacent network to stop the network functions of the products via a specially crafted packet.

    Published:Oct 30, 2020
    Last Modified:Nov 21, 2024
    EPS:Oct 30, 2020
    EPSS Score:0.00171
    CVSS Score:6.5

    Affected Products

    Vendor
    Mitsubishielectric
    Product
    Melsec Iq-rd81dl96
    Vendor
    Mitsubishielectric
    Product
    Melsec Iq-rd81dl96 Firmware
    Vendor
    Mitsubishielectric
    Product
    Melsec Iq-rd81mes96n
    Vendor
    Mitsubishielectric
    Product
    Melsec Iq-rd81mes96n Firmware
    Vendor
    Mitsubishielectric
    Product
    Melsec Iq-rd81opc96
    Vendor
    Mitsubishielectric
    Product
    Melsec Iq-rd81opc96 Firmware
    Vendor
    Mitsubishielectric
    Product
    Melsec Iq-rj71eip91
    Vendor
    Mitsubishielectric
    Product
    Melsec Iq-rj71eip91 Firmware
    Vendor
    Mitsubishielectric
    Product
    Melsec Iq-rj71pn92
    Vendor
    Mitsubishielectric
    Product
    Melsec Iq-rj71pn92 Firmware

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High