AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-5657

MEDIUM · CVSS 6.5 EPSS 1.06%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-11-02 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.5. Exploitation may require the attacker to be authenticated.

CVE
CVE-2020-5657
Severity
MEDIUM
CVSS
6.5
EPSS
1.06%

Original NVD Description

Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network Interface Module First 2 digits of serial number are '02' or before, RJ71PN92 PROFINET IO Controller Module First 2 digits of serial number are '01' or before, RD81DL96 High Speed Data Logger Module First 2 digits of serial number are '08' or before, RD81MES96N MES Interface Module First 2 digits of serial number are '04' or before, and RD81OPC96 OPC UA Server Module First 2 digits of serial number are '04' or before) allows unauthenticated attackers on adjacent network to stop the network functions of the products via a specially crafted packet.

Related CVEs

Other vulnerabilities affecting the same vendor(s)