CVE-2020-14496

Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed, tampered with, and/or destroyed.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mitsubishielectric:cpu_module_logging_configuration_tool:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:cw_configurator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:data_transfer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:em_configurator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:ezsocket:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:fr_configurator2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gt_designer3:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gt_softgot1000:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gt_softgot2000:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_logviewer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_works2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_works3:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:m_commdtm-hart:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:m_commdtm-io-link:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melfa-works:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_fielddeviceconfigurator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_navigator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mh11_settingtool_version2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:motorizer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mr_configurator2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mt_works2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mx_component:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:network_interface_board_cc-link_ver.2_utility:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:network_interface_board_cc_ie_control_utility:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:network_interface_board_cc_ie_field_utility:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:network_interface_board_mneth_utility:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:px_developer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:rt_toolbox2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:rt_toolbox3:*:*:*:*:*:*:*:*

History

07 Jun 2022, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 7.5
v3 : 9.8
CPE cpe:2.3:a:mitsubishielectric:m_commdtm-hart:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_works2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:m_commdtm-io-link:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mt_works2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:rt_toolbox3:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:network_interface_board_cc_ie_control_utility:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:cpu_module_logging_configuration_tool:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_works3:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:px_developer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:network_interface_board_cc-link_ver.2_utility:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gt_designer3:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gt_softgot2000:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:data_transfer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mr_configurator2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:motorizer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:cw_configurator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mh11_settingtool_version2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_logviewer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mx_component:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:network_interface_board_mneth_utility:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_navigator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:rt_toolbox2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:ezsocket:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_fielddeviceconfigurator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gt_softgot1000:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:fr_configurator2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:em_configurator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melfa-works:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:network_interface_board_cc_ie_field_utility:*:*:*:*:*:*:*:*
CWE CWE-275 NVD-CWE-noinfo
References (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-02 - (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-02 - Third Party Advisory, US Government Resource
First Time Mitsubishielectric
Mitsubishielectric gx Logviewer
Mitsubishielectric data Transfer
Mitsubishielectric ezsocket
Mitsubishielectric rt Toolbox2
Mitsubishielectric fr Configurator2
Mitsubishielectric m Commdtm-io-link
Mitsubishielectric gx Works3
Mitsubishielectric melsoft Navigator
Mitsubishielectric gt Softgot2000
Mitsubishielectric cpu Module Logging Configuration Tool
Mitsubishielectric network Interface Board Cc Ie Control Utility
Mitsubishielectric network Interface Board Mneth Utility
Mitsubishielectric mr Configurator2
Mitsubishielectric mh11 Settingtool Version2
Mitsubishielectric network Interface Board Cc-link Ver.2 Utility
Mitsubishielectric gx Works2
Mitsubishielectric em Configurator
Mitsubishielectric m Commdtm-hart
Mitsubishielectric mx Component
Mitsubishielectric network Interface Board Cc Ie Field Utility
Mitsubishielectric px Developer
Mitsubishielectric gt Softgot1000
Mitsubishielectric cw Configurator
Mitsubishielectric rt Toolbox3
Mitsubishielectric motorizer
Mitsubishielectric gt Designer3
Mitsubishielectric melfa-works
Mitsubishielectric mt Works2
Mitsubishielectric melsoft Fielddeviceconfigurator

19 May 2022, 18:32

Type Values Removed Values Added
New CVE

Information

Published : 2022-05-19 18:15

Updated : 2023-12-10 14:22


NVD link : CVE-2020-14496

Mitre link : CVE-2020-14496

CVE.ORG link : CVE-2020-14496


JSON object : View

Products Affected

mitsubishielectric

  • mr_configurator2
  • melsoft_navigator
  • network_interface_board_cc_ie_control_utility
  • gt_designer3
  • cw_configurator
  • px_developer
  • rt_toolbox2
  • ezsocket
  • em_configurator
  • melfa-works
  • mt_works2
  • network_interface_board_mneth_utility
  • melsoft_fielddeviceconfigurator
  • cpu_module_logging_configuration_tool
  • mx_component
  • data_transfer
  • gx_logviewer
  • m_commdtm-io-link
  • motorizer
  • mh11_settingtool_version2
  • gx_works3
  • gx_works2
  • m_commdtm-hart
  • gt_softgot2000
  • network_interface_board_cc_ie_field_utility
  • rt_toolbox3
  • network_interface_board_cc-link_ver.2_utility
  • gt_softgot1000
  • fr_configurator2
CWE
NVD-CWE-noinfo CWE-275

Permission Issues