peter bassill · operator
$ cve CVE-2020-5656 JSON

CVE-2020-5656

9.8
CRITICAL · CVSS 3.1 · EPSS 3% (pctl 87)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Improper access control vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network Interface Module First 2 digits of serial number are '02' or before, RJ71PN92 PROFINET IO Controller Module First 2 digits of serial number are '01' or before, RD81DL96 High Speed Data Logger Module First 2 digits of serial number are '08' or before, RD81MES96N MES Interface Module First 2 digits of serial number are '04' or before, and RD81OPC96 OPC UA Server Module First 2 digits of serial number are '04' or before) allows a remote unauthenticated attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS2.97% — more likely to be exploited than 87% of all CVEs
On CISA KEVno
Public exploitnone known
Published2020-11-02
Last modified2026-06-17

Affected (10)

VendorProduct
mitsubishielectricmelsec iq-rd81dl96
mitsubishielectricmelsec iq-rd81dl96 firmware
mitsubishielectricmelsec iq-rd81mes96n
mitsubishielectricmelsec iq-rd81mes96n firmware
mitsubishielectricmelsec iq-rd81opc96
mitsubishielectricmelsec iq-rd81opc96 firmware
mitsubishielectricmelsec iq-rj71eip91
mitsubishielectricmelsec iq-rj71eip91 firmware
mitsubishielectricmelsec iq-rj71pn92
mitsubishielectricmelsec iq-rj71pn92 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD