CVE-2021-20586

HIGHCVSS 7.5/10EPSS 2.74%

Last modified

CVE-2021-20586 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Resource management errors vulnerability in a robot controller of MELFA FR Series(controller "CR800-*V*D" of RV-*FR***-D-* all versions, controller "CR800-*HD" of RH-*FRH***-D-* all versions, controller "CR800-*HRD" of RH-*FRHR***-D-* all versions, controller "CR800-*V*R with R16RTCPU" of RV-*FR***-R-* all versions, controller "CR800-*HR with R16RTCPU" of RH-*FRH***-R-* all versions, controller "CR800-*HRR with R16RTCPU" of RH-*FRHR***-R-* all versions, controller "CR800-*V*Q with Q172DSRCPU" of RV-*FR***-Q-* all versions, controller "CR800-*HQ with Q172DSRCPU" of RH-*FRH***-Q-* all versions, controller "CR800-*HRQ with Q172DSRCPU" of RH-*FRHR***-Q-* all versions) and a robot controller of MELFA CR Series(controller "CR800-CVD" of RV-8CRL-D-* all versions, controller "CR800-CHD" of RH-*CRH**-D-* all versions) as well as a cooperative robot ASSISTA(controller "CR800-05VD" of RV-5AS-D-* all versions) allows a remote unauthenticated attacker to cause a DoS of the execution of the robot program and the Ethernet communication by sending a large amount of packets in burst over a short period of time. As a result of DoS, an error may occur. EPSS estimates a 2.74% chance of exploitation in the next 30 days.

Description

Resource management errors vulnerability in a robot controller of MELFA FR Series(controller "CR800-*V*D" of RV-*FR***-D-* all versions, controller "CR800-*HD" of RH-*FRH***-D-* all versions, controller "CR800-*HRD" of RH-*FRHR***-D-* all versions, controller "CR800-*V*R with R16RTCPU" of RV-*FR***-R-* all versions, controller "CR800-*HR with R16RTCPU" of RH-*FRH***-R-* all versions, controller "CR800-*HRR with R16RTCPU" of RH-*FRHR***-R-* all versions, controller "CR800-*V*Q with Q172DSRCPU" of RV-*FR***-Q-* all versions, controller "CR800-*HQ with Q172DSRCPU" of RH-*FRH***-Q-* all versions, controller "CR800-*HRQ with Q172DSRCPU" of RH-*FRHR***-Q-* all versions) and a robot controller of MELFA CR Series(controller "CR800-CVD" of RV-8CRL-D-* all versions, controller "CR800-CHD" of RH-*CRH**-D-* all versions) as well as a cooperative robot ASSISTA(controller "CR800-05VD" of RV-5AS-D-* all versions) allows a remote unauthenticated attacker to cause a DoS of the execution of the robot program and the Ethernet communication by sending a large amount of packets in burst over a short period of time. As a result of DoS, an error may occur. A reset is required to recover it if the error occurs.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
2.74%

84.3th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
MitsubishielectricRv2fr FirmwareAll versions
MitsubishielectricRv2frl FirmwareAll versions
MitsubishielectricRv4fr FirmwareAll versions
MitsubishielectricRv4frl FirmwareAll versions
MitsubishielectricRv7fr FirmwareAll versions
MitsubishielectricRv7frl FirmwareAll versions
MitsubishielectricRv7frll FirmwareAll versions
MitsubishielectricRv13fr FirmwareAll versions
MitsubishielectricRv13frl FirmwareAll versions
MitsubishielectricRv20fr FirmwareAll versions
MitsubishielectricRh1frhr FirmwareAll versions
MitsubishielectricRh3frhr FirmwareAll versions
MitsubishielectricRh3frh35 FirmwareAll versions
MitsubishielectricRh3frh45 FirmwareAll versions
MitsubishielectricRh3frh55 FirmwareAll versions
MitsubishielectricRh6frh35 FirmwareAll versions
MitsubishielectricRh6frh45 FirmwareAll versions
MitsubishielectricRh6frh55 FirmwareAll versions
MitsubishielectricRh12frh55 FirmwareAll versions
MitsubishielectricRh12rfh70 FirmwareAll versions
MitsubishielectricRh12frh85 FirmwareAll versions
MitsubishielectricRh20frh85 FirmwareAll versions
MitsubishielectricRh20frh100 FirmwareAll versions
MitsubishielectricRv2fr\(B\) FirmwareAll versions
MitsubishielectricRv2frl\(B\) FirmwareAll versions
MitsubishielectricRv4frm\/C FirmwareAll versions
MitsubishielectricRv4frlm\/C FirmwareAll versions
MitsubishielectricRv7frm\/C FirmwareAll versions
MitsubishielectricRv7frlm\/C FirmwareAll versions
MitsubishielectricRv7frllm\/C FirmwareAll versions
MitsubishielectricRv13frm\/C FirmwareAll versions
MitsubishielectricRv13frlm\/C FirmwareAll versions
MitsubishielectricRv20frm\/C FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-20586?
Resource management errors vulnerability in a robot controller of MELFA FR Series(controller "CR800-*V*D" of RV-*FR***-D-* all versions, controller "CR800-*HD" of RH-*FRH***-D-* all versions, controller "CR800-*HRD" of RH-*FRHR***-D-* all versions, controller "CR800-*V*R with R16RTCPU" of RV-*FR***-R-* all versions, controller "CR800-*HR with R16RTCPU" of RH-*FRH***-R-* all versions, controller "CR800-*HRR with R16RTCPU" of RH-*FRHR***-R-* all versions, controller "CR800-*V*Q with Q172DSRCPU" of RV-*FR***-Q-* all versions, controller "CR800-*HQ with Q172DSRCPU" of RH-*FRH***-Q-* all versions, controller "CR800-*HRQ with Q172DSRCPU" of RH-*FRHR***-Q-* all versions) and a robot controller of MELFA CR Series(controller "CR800-CVD" of RV-8CRL-D-* all versions, controller "CR800-CHD" of RH-*CRH**-D-* all versions) as well as a cooperative robot ASSISTA(controller "CR800-05VD" of RV-5AS-D-* all versions) allows a remote unauthenticated attacker to cause a DoS of the execution of the robot program and the Ethernet communication by sending a large amount of packets in burst over a short period of time. As a result of DoS, an error may occur. A reset is required to recover it if the error occurs.
How severe is CVE-2021-20586?
CVE-2021-20586 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 2.74% probability of exploitation in the next 30 days.
How do I fix CVE-2021-20586?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-20586?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST