CVE-2020-16850 - CVE House
Back to Database
Status published High CVE-2020-16850

Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an...

Vulnerability Description

Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over the network. This denial of service attack exposes Improper Input Validation. After halting, physical access to the PLC is required in order to restore production, and the device state is lost. This is related to R04CPU, RJ71GF11-T2, R04CPU, and RJ71GF11-T2.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-16850

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

mitsubishielectric

View all reports →

Affected Software

r00cpu firmware, r01cpu firmware, r02cpu firmware, r04cpu firmware, r08cpu firmware, r16cpu firmware, r32cpu firmware, r120cpu firmware, r08sfcpu firmware, r16sfcpu firmware, r32sfcpu firmware, r120sfcpu firmware, r08pcpu firmware, r16pcpu firmware, r32pcpu firmware, r120pcpu firmware, r16mtcpu firmware, r32mtcpu firmware, r64mtcpu firmware
Vulnerable Versions:
0

Timeline

Official Publish: November 30th, 2020
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.