CWE
276 428
Advisory Published
Updated

CVE-2020-14521: Mitsubishi Electric Factory Automation Engineering Products Unquoted Search Path or Element

First published: Fri Feb 11 2022(Updated: )

Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.

Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov

Affected SoftwareAffected VersionHow to fix
Mitsubishielectric C Controller Interface Module Utility
Mitsubishielectric C Controller Module Setting And Monitoring Tool
Mitsubishielectric Cc-link Ie Control Network Data Collector=1.00a
Mitsubishielectric Cc-link Ie Field Network Data Collector=1.00a
Mitsubishielectric Cc-link Ie Tsn Data Collector=1.00a
Mitsubishielectric Cpu Module Logging Configuration Tool<=1.100e
Mitsubishielectric Cw Configurator<=1.010l
Mitsubishielectric Data Transfer<=3.42u
Mitsubishielectric Ezsocket<=5.1
Mitsubishielectric Fr Configurator Sw3
Mitsubishielectric Fr Configurator2
Mitsubishielectric Gt Designer2 Classic
Mitsubishielectric Gt Softgot1000>=3.0<=3.200j
Mitsubishielectric Gt Softgot2000>=1.0<=1.241b
Mitsubishielectric Gx Developer<=8.504a
Mitsubishielectric Gx Logviewer<=1.100e
Mitsubishielectric Gx Works2<=1.601b
Mitsubishielectric Gx Works3<=1.063r
Mitsubishielectric M Commdtm-io-link
Mitsubishielectric Melfa-works<=4.4
Mitsubishielectric Melsec Wincpu Setting Utility
Mitsubishielectric Melsoft Complete Clean Up Tool<=1.06g
Mitsubishielectric Melsoft Em Software Development Kit
Mitsubishielectric Melsoft Iq Appportal<=1.17t
Mitsubishielectric Melsoft Navigator<=2.74c
Mitsubishielectric Mi Configurator
Mitsubishielectric Motion Control Setting<=1.005f
Mitsubishielectric Motorizer<=1.005f
Mitsubishielectric Mr Configurator2<=1.125f
Mitsubishielectric Mt Works2<=1.167z
Mitsubishielectric Mtconnect Data Collector<=1.1.4.0
Mitsubishielectric Mx Component<=4.20w
Mitsubishielectric Mx Mesinterface<=1.21x
Mitsubishielectric Mx Mesinterface-r<=1.12n
Mitsubishielectric Mx Sheet<=2.15r
Mitsubishielectric Position Board Utility 2
Mitsubishielectric Px Developer<=1.53f
Mitsubishielectric Rt Toolbox2<=3.73b
Mitsubishielectric Rt Toolbox3<=1.82l
Mitsubishielectric Setting\/monitoring Tools For The C Controller Module
Mitsubishielectric Slmp Data Collector<=1.04e
Mitsubishielectric Gt Designer3<=1.241b
Mitsubishielectric Got1000 Series Gt10
Mitsubishielectric Got1000 Series Gt11
Mitsubishielectric Got1000 Series Gt12
Mitsubishielectric Got1000 Series Gt14
Mitsubishielectric Got1000 Series Gt15
Mitsubishielectric Got1000 Series Gt16
Mitsubishielectric Got1000 Series Gt21
Mitsubishielectric Got1000 Series Gt23
Mitsubishielectric Got1000 Series Gt25
Mitsubishielectric Got1000 Series Gt27
Mitsubishielectric Network Interface Board Cc-link Ver.2 Utility Firmware
Mitsubishielectric Network Interface Board Cc-link Ver.2 Utility
Mitsubishielectric Network Interface Board Cc Ie Control Utility Firmware
Mitsubishielectric Network Interface Board Cc Ie Control Utility
Mitsubishielectric Network Interface Board Cc Ie Field Utility Firmware
Mitsubishielectric Network Interface Board Cc Ie Field Utility
Mitsubishielectric Network Interface Board Mneth Utility Firmware
Mitsubishielectric Network Interface Board Mneth Utility
Mitsubishi Electric Data Transfer, Versions 3.42U and prior
Mitsubishi Electric EZSocket, version 5.1 and prior
Mitsubishi Electric FR Configurator SW3, all versions
Mitsubishi Electric FR Configurator2: Versions 1.26C and prior
Mitsubishi Electric GT Designer2 Classic, all versions
Mitsubishi Electric GT Designer3 Version1 (GOT1000), Versions 1.241B and prior
Mitsubishi Electric GT Designer3 Version1 (GOT2000), Versions 1.241B and prior
Mitsubishi Electric GT SoftGOT1000 Version3, Versions 3.200J and prior
Mitsubishi Electric GT SoftGOT2000 Version1, Versions 1.241B and prior
Mitsubishi Electric GX Developer, Versions 8.504A and prior
Mitsubishi Electric GX LogViewer, Versions 1.100E and prior
Mitsubishi Electric GX Works2, Versions 1.601B and prior
Mitsubishi Electric GX Works3, Versions 1.063R and prior
Mitsubishi Electric M_CommDTM-IO-Link, Versions 1.03D and prior
Mitsubishi Electric MELFA-Works: Version 4.4 and prior
Mitsubishi Electric MELSEC WinCPU Setting Utility, all versions
Mitsubishi Electric MELSOFT Complete Clean Up Tool, Versions 1.06G and prior
Mitsubishi Electric MELSOFT EM Software Development Kit, Versions 1.015R and prior
Mitsubishi Electric MELSOFT iQ AppPortal, 1.17T and prior
Mitsubishi Electric MELSOFT Navigator, Versions 2.74C and prior
Mitsubishi Electric MI Configurator, Version 1.004E and prior
Mitsubishi Electric Motion Control Setting, Versions 1.005F and prior
Mitsubishi Electric Motorizer, Versions 1.005F and prior
Mitsubishi Electric MR Configurator2, Version 1.125F and prior
Mitsubishi Electric MT Works2, Version 1.167Z and prior
Mitsubishi Electric MTConnect Data Collector, Version 1.1.4.0 and prior
Mitsubishi Electric MX Component, Version 4.20W and prior
Mitsubishi Electric MX MESInterface, Versions 1.21X and prior
Mitsubishi Electric MX MESInterface-R, Versions 1.12N and prior
Mitsubishi Electric MX Sheet, Version 2.15R and prior
Mitsubishi Electric Network Interface Board CC IE Control Utility, Versions 1.29F and prior
Mitsubishi Electric Network Interface Board CC IE Field Utility, Versions 1.16S and prior
Mitsubishi Electric Network Interface Board CC-Link Ver.2 Utility, Versions 1.23Z and prior
Mitsubishi Electric Network Interface Board MNETH Utility, Versions 34L and prior
Mitsubishi Electric Position Board Utility 2<=3.20
Mitsubishi Electric PX Developer, version 1.53F and prior
Mitsubishi Electric RT ToolBox2: Version 3.73B and prior
Mitsubishi Electric RT ToolBox3: Version 1.82L and prior
Mitsubishi Electric Setting/Monitoring tools for the C Controller module (SW3PVC-CCPU), Version 3.13P and prior
Mitsubishi Electric Setting/Monitoring tools for the C Controller module (SW4PVC-CCPU), Version 4.12N and prior
Mitsubishi Electric SLMP Data Collector, Version 1.04E and prior
All of
Mitsubishielectric Gt Designer3<=1.241b
Any of
Mitsubishielectric Got1000 Series Gt10
Mitsubishielectric Got1000 Series Gt11
Mitsubishielectric Got1000 Series Gt12
Mitsubishielectric Got1000 Series Gt14
Mitsubishielectric Got1000 Series Gt15
Mitsubishielectric Got1000 Series Gt16
Mitsubishielectric Got1000 Series Gt21
Mitsubishielectric Got1000 Series Gt23
Mitsubishielectric Got1000 Series Gt25
Mitsubishielectric Got1000 Series Gt27
All of
Mitsubishielectric Network Interface Board Cc-link Ver.2 Utility Firmware
Mitsubishielectric Network Interface Board Cc-link Ver.2 Utility
All of
Mitsubishielectric Network Interface Board Cc Ie Control Utility Firmware
Mitsubishielectric Network Interface Board Cc Ie Control Utility
All of
Mitsubishielectric Network Interface Board Cc Ie Field Utility Firmware
Mitsubishielectric Network Interface Board Cc Ie Field Utility
All of
Mitsubishielectric Network Interface Board Mneth Utility Firmware
Mitsubishielectric Network Interface Board Mneth Utility

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Parent vulnerabilities

(Appears in the following advisories)

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203