Resource exhaustion in MELSEC-Q QJ71E71-100 - CVE-2019-10977
Published: May 21, 2019
MELSEC-Q QJ71E71-100
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within FTP server implementation. A remote attacker can send specially crafted TCP packets to the FTP service, force the device to enter an error mode and perform a denial of service (DoS) attack. Physical reset of the PLC is required to regain device functionality.