CVE-2020-14496: Mitsubishi Electric Multiple Factory Automation Engineering Software Products (Update A) - Permission Issues
Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed, tampered with, and/or destroyed.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-14496?
CVE-2020-14496 is a vulnerability that allows an attacker to escalate privilege and execute malicious programs in multiple Mitsubishi Electric Factory Automation Engineering Software Products.
How severe is CVE-2020-14496?
CVE-2020-14496 has a severity rating of 9.8, which is considered critical.
Which Mitsubishi Electric software products are affected by CVE-2020-14496?
The following Mitsubishi Electric software products are affected: CPU Module Logging Configuration Tool, CW Configurator, Data Transfer, EM Configurator, EZSocket, FR Configurator2, GT Designer3, GT SoftGOT1000, GT SoftGOT2000, GX LogViewer, GX Works2, GX Works3, M Commdtm-HART, M Commdtm-IO-Link, MELFA-Works, Melsoft Fielddeviceconfigurator, Melsoft Navigator, MH11 Settingtool Version2, Motorizer, MR Configurator2, MT Works2, MX Component, Network Interface Board CC-Link Ver.2 Utility, Network Interface Board CC IE Control Utility, Network Interface Board CC IE Field Utility, Network Interface Board MNETH Utility, PX Developer, RT Toolbox2, and RT Toolbox3.
What can an attacker do if they exploit CVE-2020-14496?
If CVE-2020-14496 is successfully exploited, an attacker can escalate privilege, execute malicious programs, cause a denial-of-service condition, and access information.
Is there a fix available for CVE-2020-14496?
It is recommended to apply the latest patches and updates provided by Mitsubishi Electric to fix CVE-2020-14496.