cve/2021/CVE-2021-20610.md

99 lines
10 KiB
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2021-20610](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20610)
![](https://img.shields.io/static/v1?label=Product&message=MELIPC%20Series%20MI5122-VW&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20L%20Series%20L02CPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20L%20Series%20L02CPU-P&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20L%20Series%20L06CPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20L%20Series%20L06CPU-P&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20L%20Series%20L26CPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20L%20Series%20L26CPU-BT&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20L%20Series%20L26CPU-P&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20L%20Series%20L26CPU-PBT&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20MR-MQ100&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q03UDECPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q03UDVCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q04UDEHCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q04UDPVCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q04UDVCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q06UDEHCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q06UDPVCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q06UDVCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q100UDEHCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q10UDEHCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q12DCCPU-V&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q13UDEHCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q13UDPVCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q13UDVCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q170MCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q170MSCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q170MSCPU-S1&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q172DCPU-S1&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q172DSCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q173DCPU-S1&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q173DSCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q20UDEHCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q24DHCCPU-LS&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q24DHCCPU-V%20&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q24DHCCPU-VG&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q26DHCCPU-LS&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q26UDEHCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q26UDPVCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q26UDVCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20Q%20Series%20Q50UDEHCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R00CPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R01CPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R02CPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R04CPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R04ENCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R08CPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R08ENCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R08PCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R08PSFCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R08SFCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R120CPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R120ENCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R120PCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R120PSFCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R120SFCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R12CCPU-V&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R16CPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R16ENCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R16MTCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R16PCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R16PSFCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R16SFCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R32CPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R32ENCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R32MTCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R32PCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R32PSFCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R32SFCPU&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MELSEC%20iQ-R%20Series%20R64MTCPU&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20Firmware%20versions%20%2205%22%20and%20prior%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20Firmware%20versions%20%2208%22%20and%20prior%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20Firmware%20versions%20%2216%22%20and%20prior%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20Firmware%20versions%20%2224%22%20and%20prior%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20Firmware%20versions%20%2226%22%20and%20prior%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20Firmware%20versions%20%2229%22%20and%20prior%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20Firmware%20versions%20%2257%22%20and%20prior%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20Operating%20system%20software%20version%20%2223%22%20and%20prior%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20Operating%20system%20software%20version%20%22F%22%20and%20prior%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20Operating%20system%20software%20version%20%22W%22%20and%20prior%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20Operating%20system%20software%20version%20%22Y%22%20and%20prior%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20The%20first%205%20digits%20of%20serial%20No.%20%2223071%22%20and%20prior%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20The%20first%205%20digits%20of%20serial%20No.%20%2223121%22%20and%20prior%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20The%20first%205%20digits%20of%20serial%20No.%20%2224031%22%20and%20prior%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-130%20Improper%20Handling%20of%20Length%20Parameter%20Inconsistency&color=brighgreen)
### Description
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, MELSEC iQ-R Series R08/16/32/120PCPU, MELSEC iQ-R Series R08/16/32/120PSFCPU, MELSEC iQ-R Series R16/32/64MTCPU, MELSEC iQ-R Series R12CCPU-V, MELSEC Q Series Q03UDECPU, MELSEC Q Series Q04/06/10/13/20/26/50/100UDEHCPU, MELSEC Q Series Q03/04/06/13/26UDVCPU, MELSEC Q Series Q04/06/13/26UDPVCPU, MELSEC Q Series Q12DCCPU-V, MELSEC Q Series Q24DHCCPU-V(G), MELSEC Q Series Q24/26DHCCPU-LS, MELSEC Q Series MR-MQ100, MELSEC Q Series Q172/173DCPU-S1, MELSEC Q Series Q172/173DSCPU, MELSEC Q Series Q170MCPU, MELSEC Q Series Q170MSCPU(-S1), MELSEC L Series L02/06/26CPU(-P), MELSEC L Series L26CPU-(P)BT and MELIPC Series MI5122-VW allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by sending specially crafted packets. System reset is required for recovery.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds