CVE-2021-20591

HIGH

Mitsubishi Electric MELSEC iQ-R - DoS

Title source: llm
STIX 2.1

Description

Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R00/01/02CPU all versions, R04/08/16/32/120(EN)CPU all versions, R08/16/32/120SFCPU all versions, R08/16/32/120PCPU all versions, R08/16/32/120PSFCPU all versions) allows a remote unauthenticated attacker to prevent legitimate clients from connecting to the MELSOFT transmission port (TCP/IP) by not closing a connection properly, which may lead to a denial of service (DoS) condition.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://jvn.jp/vu/JVNVU98060539/index.html

Scores

CVSS v3 7.5
EPSS 0.0050
EPSS Percentile 66.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-400
Status published
Products (20)
mitsubishielectric/r00cpu_firmware
mitsubishielectric/r01cpu_firmware
mitsubishielectric/r02cpu_firmware
mitsubishielectric/r04cpu_firmware
mitsubishielectric/r08cpu_firmware
mitsubishielectric/r08pcpu_firmware
mitsubishielectric/r08psfcpu_firmware
mitsubishielectric/r08sfcpu_firmware
mitsubishielectric/r120cpu_firmware
mitsubishielectric/r120pcpu_firmware
... and 10 more
Published Jun 11, 2021
Tracked Since Feb 18, 2026