CVE-2020-14521

Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mitsubishielectric:c_controller_interface_module_utility:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:c_controller_module_setting_and_monitoring_tool:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:cc-link_ie_control_network_data_collector:1.00a:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:cc-link_ie_field_network_data_collector:1.00a:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:cc-link_ie_tsn_data_collector:1.00a:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:cpu_module_logging_configuration_tool:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:cw_configurator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:data_transfer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:ezsocket:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:fr_configurator_sw3:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:fr_configurator2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gt_designer2_classic:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gt_softgot1000:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gt_softgot2000:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_developer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_logviewer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_works2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_works3:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:m_commdtm-io-link:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melfa-works:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsec_wincpu_setting_utility:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_complete_clean_up_tool:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_em_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_iq_appportal:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_navigator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mi_configurator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:motion_control_setting:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:motorizer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mr_configurator2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mt_works2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mtconnect_data_collector:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mx_component:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mx_mesinterface:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mx_mesinterface-r:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mx_sheet:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:position_board_utility_2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:px_developer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:rt_toolbox2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:rt_toolbox3:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:setting\/monitoring_tools_for_the_c_controller_module:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:slmp_data_collector:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:mitsubishielectric:gt_designer3:*:*:*:*:*:*:*:*
OR cpe:2.3:h:mitsubishielectric:got1000_series_gt10:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:got1000_series_gt11:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:got1000_series_gt12:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:got1000_series_gt14:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:got1000_series_gt15:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:got1000_series_gt16:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:got1000_series_gt21:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:got1000_series_gt23:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:got1000_series_gt25:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:got1000_series_gt27:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:mitsubishielectric:network_interface_board_cc-link_ver.2_utility_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:network_interface_board_cc-link_ver.2_utility:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:mitsubishielectric:network_interface_board_cc_ie_control_utility_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:network_interface_board_cc_ie_control_utility:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:mitsubishielectric:network_interface_board_cc_ie_field_utility_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:network_interface_board_cc_ie_field_utility:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:mitsubishielectric:network_interface_board_mneth_utility_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:network_interface_board_mneth_utility:-:*:*:*:*:*:*:*

History

07 Nov 2023, 03:17

Type Values Removed Values Added
Summary Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition. Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.

10 Mar 2022, 16:42

Type Values Removed Values Added
First Time Mitsubishielectric got1000 Series Gt27
Mitsubishielectric network Interface Board Cc-link Ver.2 Utility Firmware
Mitsubishielectric got1000 Series Gt25
Mitsubishielectric got1000 Series Gt15
Mitsubishielectric got1000 Series Gt14
Mitsubishielectric got1000 Series Gt10
Mitsubishielectric network Interface Board Cc Ie Control Utility Firmware
Mitsubishielectric got1000 Series Gt21
Mitsubishielectric got1000 Series Gt11
Mitsubishielectric network Interface Board Cc Ie Field Utility Firmware
Mitsubishielectric gt Designer3
Mitsubishielectric got1000 Series Gt23
Mitsubishielectric got1000 Series Gt12
Mitsubishielectric got1000 Series Gt16
Mitsubishielectric network Interface Board Mneth Utility Firmware
CPE cpe:2.3:a:mitsubishielectric:gt_designer2_classic:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:got1000:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:network_interface_board_cc-link_ver.2_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:m_commdtm-io-link:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:c_controller_module_setting_and_monitoring_tool:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:network_interface_board_cc_ie_control_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_em_software_development_kit:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:network_interface_board_cc_ie_field_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mi_configurator:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:fr_configurator2:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:setting\/monitoring_tools_for_the_c_controller_module:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:slmp_data_collector:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:position_board_utility_2:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsec_wincpu_setting_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:network_interface_board_mneth_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:got2000:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:fr_configurator_sw3:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:got1000_series_gt27:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:fr_configurator_sw3:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:got1000_series_gt12:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gt_designer3:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_em_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:position_board_utility_2:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:network_interface_board_cc-link_ver.2_utility_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:fr_configurator2:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:network_interface_board_cc_ie_control_utility:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:got1000_series_gt11:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:got1000_series_gt15:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:got1000_series_gt25:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:network_interface_board_mneth_utility_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:network_interface_board_cc_ie_field_utility_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:setting\/monitoring_tools_for_the_c_controller_module:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:got1000_series_gt10:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:got1000_series_gt14:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:got1000_series_gt16:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:c_controller_module_setting_and_monitoring_tool:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:slmp_data_collector:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:network_interface_board_cc_ie_field_utility:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:got1000_series_gt21:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsec_wincpu_setting_utility:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gt_designer2_classic:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:network_interface_board_cc-link_ver.2_utility:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:network_interface_board_mneth_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:m_commdtm-io-link:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mi_configurator:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:network_interface_board_cc_ie_control_utility_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:got1000_series_gt23:-:*:*:*:*:*:*:*

22 Feb 2022, 18:14

Type Values Removed Values Added
References (MISC) https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-007_en.pdf - (MISC) https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-007_en.pdf - Vendor Advisory
References (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-04 - (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-04 - Third Party Advisory, US Government Resource
CPE cpe:2.3:a:mitsubishielectric:gt_designer2_classic:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mx_mesinterface:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gt_softgot2000:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_iq_appportal:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mx_component:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:c_controller_module_setting_and_monitoring_tool:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:motion_control_setting:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:network_interface_board_cc_ie_control_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:cc-link_ie_tsn_data_collector:1.00a:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:data_transfer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mt_works2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melfa-works:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:cc-link_ie_field_network_data_collector:1.00a:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mx_sheet:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:ezsocket:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:c_controller_interface_module_utility:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:setting\/monitoring_tools_for_the_c_controller_module:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gt_softgot1000:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mr_configurator2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_navigator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_developer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:fr_configurator_sw3:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:network_interface_board_cc_ie_field_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:px_developer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_works3:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:slmp_data_collector:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mtconnect_data_collector:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:position_board_utility_2:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:cpu_module_logging_configuration_tool:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:motorizer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:network_interface_board_mneth_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:got2000:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_works2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:rt_toolbox3:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:got1000:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:m_commdtm-io-link:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:rt_toolbox2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_complete_clean_up_tool:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_em_software_development_kit:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:cc-link_ie_control_network_data_collector:1.00a:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_logviewer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mi_configurator:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:fr_configurator2:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsec_wincpu_setting_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mx_mesinterface-r:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:cw_configurator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:network_interface_board_cc-link_ver.2_utility:-:*:*:*:*:*:*:*
First Time Mitsubishielectric setting\/monitoring Tools For The C Controller Module
Mitsubishielectric
Mitsubishielectric position Board Utility 2
Mitsubishielectric cpu Module Logging Configuration Tool
Mitsubishielectric network Interface Board Cc Ie Control Utility
Mitsubishielectric mx Mesinterface
Mitsubishielectric melfa-works
Mitsubishielectric melsoft Em Software Development Kit
Mitsubishielectric slmp Data Collector
Mitsubishielectric gx Works3
Mitsubishielectric data Transfer
Mitsubishielectric gt Softgot1000
Mitsubishielectric motorizer
Mitsubishielectric c Controller Interface Module Utility
Mitsubishielectric melsec Wincpu Setting Utility
Mitsubishielectric melsoft Complete Clean Up Tool
Mitsubishielectric motion Control Setting
Mitsubishielectric rt Toolbox2
Mitsubishielectric cc-link Ie Tsn Data Collector
Mitsubishielectric mi Configurator
Mitsubishielectric melsoft Iq Appportal
Mitsubishielectric mx Component
Mitsubishielectric gx Developer
Mitsubishielectric gt Designer2 Classic
Mitsubishielectric gt Softgot2000
Mitsubishielectric mx Sheet
Mitsubishielectric gx Works2
Mitsubishielectric rt Toolbox3
Mitsubishielectric network Interface Board Cc Ie Field Utility
Mitsubishielectric m Commdtm-io-link
Mitsubishielectric cw Configurator
Mitsubishielectric c Controller Module Setting And Monitoring Tool
Mitsubishielectric got1000
Mitsubishielectric network Interface Board Mneth Utility
Mitsubishielectric fr Configurator Sw3
Mitsubishielectric melsoft Navigator
Mitsubishielectric mx Mesinterface-r
Mitsubishielectric network Interface Board Cc-link Ver.2 Utility
Mitsubishielectric ezsocket
Mitsubishielectric cc-link Ie Field Network Data Collector
Mitsubishielectric gx Logviewer
Mitsubishielectric got2000
Mitsubishielectric mtconnect Data Collector
Mitsubishielectric fr Configurator2
Mitsubishielectric mr Configurator2
Mitsubishielectric cc-link Ie Control Network Data Collector
Mitsubishielectric px Developer
Mitsubishielectric mt Works2
CWE CWE-276
CVSS v2 : unknown
v3 : unknown
v2 : 7.5
v3 : 9.8

17 Feb 2022, 15:15

Type Values Removed Values Added
References
  • (MISC) https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-007_en.pdf -

11 Feb 2022, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-02-11 18:15

Updated : 2023-12-10 14:22


NVD link : CVE-2020-14521

Mitre link : CVE-2020-14521

CVE.ORG link : CVE-2020-14521


JSON object : View

Products Affected

mitsubishielectric

  • gx_logviewer
  • got1000_series_gt11
  • slmp_data_collector
  • got1000_series_gt23
  • ezsocket
  • motion_control_setting
  • network_interface_board_cc_ie_control_utility_firmware
  • m_commdtm-io-link
  • melsoft_navigator
  • fr_configurator2
  • data_transfer
  • setting\/monitoring_tools_for_the_c_controller_module
  • cpu_module_logging_configuration_tool
  • mx_mesinterface-r
  • gt_designer2_classic
  • melsec_wincpu_setting_utility
  • got1000_series_gt12
  • network_interface_board_cc_ie_control_utility
  • melsoft_em_software_development_kit
  • gt_softgot1000
  • gt_designer3
  • got1000_series_gt16
  • melfa-works
  • got1000_series_gt10
  • got1000_series_gt21
  • mi_configurator
  • cc-link_ie_tsn_data_collector
  • melsoft_complete_clean_up_tool
  • got1000_series_gt14
  • mx_sheet
  • network_interface_board_cc_ie_field_utility_firmware
  • mx_component
  • network_interface_board_mneth_utility_firmware
  • position_board_utility_2
  • network_interface_board_cc-link_ver.2_utility_firmware
  • cw_configurator
  • mt_works2
  • cc-link_ie_control_network_data_collector
  • c_controller_module_setting_and_monitoring_tool
  • motorizer
  • c_controller_interface_module_utility
  • fr_configurator_sw3
  • gt_softgot2000
  • mr_configurator2
  • got1000_series_gt25
  • gx_works2
  • network_interface_board_cc-link_ver.2_utility
  • mx_mesinterface
  • gx_works3
  • got1000_series_gt27
  • cc-link_ie_field_network_data_collector
  • rt_toolbox2
  • mtconnect_data_collector
  • rt_toolbox3
  • network_interface_board_cc_ie_field_utility
  • melsoft_iq_appportal
  • network_interface_board_mneth_utility
  • px_developer
  • gx_developer
  • got1000_series_gt15
CWE
CWE-276

Incorrect Default Permissions

CWE-428

Unquoted Search Path or Element