CVE-2020-14521
11.02.2022, 18:15
Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.Enginsight
Vendor | Product | Version |
---|---|---|
mitsubishielectric | c_controller_interface_module_utility | * |
mitsubishielectric | c_controller_module_setting_and_monitoring_tool | * |
mitsubishielectric | cc-link_ie_control_network_data_collector | 1.00a:a |
mitsubishielectric | cc-link_ie_field_network_data_collector | 1.00a:a |
mitsubishielectric | cc-link_ie_tsn_data_collector | 1.00a:a |
mitsubishielectric | cpu_module_logging_configuration_tool | 𝑥 ≤ 1.100e |
mitsubishielectric | cw_configurator | 𝑥 ≤ 1.010l |
mitsubishielectric | data_transfer | 𝑥 ≤ 3.42u |
mitsubishielectric | ezsocket | 𝑥 ≤ 5.1 |
mitsubishielectric | fr_configurator_sw3 | * |
mitsubishielectric | fr_configurator2 | * |
mitsubishielectric | gt_designer2_classic | * |
mitsubishielectric | gt_softgot1000 | 3.0 ≤ 𝑥 ≤ 3.200j |
mitsubishielectric | gt_softgot2000 | 1.0 ≤ 𝑥 ≤ 1.241b |
mitsubishielectric | gx_developer | 𝑥 ≤ 8.504a |
mitsubishielectric | gx_logviewer | 𝑥 ≤ 1.100e |
mitsubishielectric | gx_works2 | 𝑥 ≤ 1.601b |
mitsubishielectric | gx_works3 | 𝑥 ≤ 1.063r |
mitsubishielectric | m_commdtm-io-link | * |
mitsubishielectric | melfa-works | 𝑥 ≤ 4.4 |
mitsubishielectric | melsec_wincpu_setting_utility | * |
mitsubishielectric | melsoft_complete_clean_up_tool | 𝑥 ≤ 1.06g |
mitsubishielectric | melsoft_em_software_development_kit | * |
mitsubishielectric | melsoft_iq_appportal | 𝑥 ≤ 1.17t |
mitsubishielectric | melsoft_navigator | 𝑥 ≤ 2.74c |
mitsubishielectric | mi_configurator | * |
mitsubishielectric | motion_control_setting | 𝑥 ≤ 1.005f |
mitsubishielectric | motorizer | 𝑥 ≤ 1.005f |
mitsubishielectric | mr_configurator2 | 𝑥 ≤ 1.125f |
mitsubishielectric | mt_works2 | 𝑥 ≤ 1.167z |
mitsubishielectric | mtconnect_data_collector | 𝑥 ≤ 1.1.4.0 |
mitsubishielectric | mx_component | 𝑥 ≤ 4.20w |
mitsubishielectric | mx_mesinterface | 𝑥 ≤ 1.21x |
mitsubishielectric | mx_mesinterface-r | 𝑥 ≤ 1.12n |
mitsubishielectric | mx_sheet | 𝑥 ≤ 2.15r |
mitsubishielectric | position_board_utility_2 | * |
mitsubishielectric | px_developer | 𝑥 ≤ 1.53f |
mitsubishielectric | rt_toolbox2 | 𝑥 ≤ 3.73b |
mitsubishielectric | rt_toolbox3 | 𝑥 ≤ 1.82l |
mitsubishielectric | setting\/monitoring_tools_for_the_c_controller_module | * |
mitsubishielectric | slmp_data_collector | 𝑥 ≤ 1.04e |
mitsubishielectric | gt_designer3 | 𝑥 ≤ 1.241b |
mitsubishielectric | network_interface_board_cc-link_ver.2_utility_firmware | * |
mitsubishielectric | network_interface_board_cc_ie_control_utility_firmware | * |
mitsubishielectric | network_interface_board_cc_ie_field_utility_firmware | * |
mitsubishielectric | network_interface_board_mneth_utility_firmware | * |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-428 - Unquoted Search Path or ElementThe product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
- CWE-276 - Incorrect Default PermissionsDuring installation, installed file permissions are set to allow anyone to modify those files.