Vulnerability record · CVE-2020-5666 · published 16 November 2020
CVE-2020-5666: Mitsubishielectric melsec iq-r00 firmware uncontrolled resource consumption vulnerability
Mitsubishielectric · Melsec Iq R00 Firmware
Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '05' to '19' and R04/08/16/32/120(EN)CPU Firmware versions from '35' to '51') allows a remote attacker to cause an error in a CPU unit via a specially crafted HTTP packet, which may lead to a denial-of-service (DoS) condition in execution of the program and its communication.
Description
Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '05' to '19' and R04/08/16/32/120(EN)CPU Firmware versions from '35' to '51') allows a remote attacker to cause an error in a CPU unit via a specially crafted HTTP packet, which may lead to a denial-of-service (DoS) condition in execution of the program and its communication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://jvn.jp/en/jp/JVN44764844/index.html | Third Party Advisory |
| https://jvn.jp/jp/JVN44764844/index.html | Third Party Advisory |
| https://us-cert.cisa.gov/ics/advisories/icsa-20-317-01 | Third Party AdvisoryUS Government Resource |
| https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-015_en.pdf | MitigationVendor Advisory |
| https://jvn.jp/en/jp/JVN44764844/index.html | Third Party Advisory |
| https://jvn.jp/jp/JVN44764844/index.html | Third Party Advisory |
| https://us-cert.cisa.gov/ics/advisories/icsa-20-317-01 | Third Party AdvisoryUS Government Resource |
| https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-015_en.pdf | MitigationVendor Advisory |
Track CVE-2020-5666 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-5666), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.