Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.
References
| Link | Resource |
|---|---|
| https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-04 | Third Party Advisory US Government Resource |
| https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-007_en.pdf | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-02-11 18:15
Updated : 2022-02-22 18:14
NVD link : CVE-2020-14521
Mitre link : CVE-2020-14521
JSON object : View
Products Affected
mitsubishielectric
- setting\/monitoring_tools_for_the_c_controller_module
- c_controller_module_setting_and_monitoring_tool
- melsoft_complete_clean_up_tool
- got2000
- motorizer
- gx_developer
- mi_configurator
- px_developer
- gt_softgot1000
- network_interface_board_cc-link_ver.2_utility
- mtconnect_data_collector
- mx_mesinterface
- network_interface_board_cc_ie_field_utility
- rt_toolbox2
- rt_toolbox3
- fr_configurator_sw3
- c_controller_interface_module_utility
- cc-link_ie_control_network_data_collector
- m_commdtm-io-link
- motion_control_setting
- melsoft_iq_appportal
- melsoft_em_software_development_kit
- melsoft_navigator
- cc-link_ie_tsn_data_collector
- fr_configurator2
- gx_works3
- mx_mesinterface-r
- melfa-works
- mr_configurator2
- mt_works2
- cc-link_ie_field_network_data_collector
- mx_sheet
- cw_configurator
- network_interface_board_cc_ie_control_utility
- melsec_wincpu_setting_utility
- gt_softgot2000
- cpu_module_logging_configuration_tool
- gx_works2
- slmp_data_collector
- got1000
- gx_logviewer
- position_board_utility_2
- ezsocket
- network_interface_board_mneth_utility
- mx_component
- data_transfer
- gt_designer2_classic
CWE
CWE-276
Incorrect Default Permissions
