CWE
276 428
Advisory Published
Updated

CVE-2020-14521: Mitsubishi Electric Factory Automation Engineering Products Unquoted Search Path or Element

First published: Fri Feb 11 2022(Updated: )

Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.

Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov

Affected SoftwareAffected VersionHow to fix
Mitsubishi Electric C Controller Interface Module Utility
Mitsubishi Electric CC-Link IE Control Network Data Collector
Mitsubishi Electric CC-Link IE Field Network Data Collector
Mitsubishi Electric CC-Link IE TSN Data Collector
Mitsubishi Electric CPU Module Logging Configuration Tool
Mitsubishi Electric CW Configurator
Mitsubishi Electric Data Transfer
Mitsubishi Electric EZSocket
Mitsubishi Electric FR Configurator
Mitsubishi Electric FR Configurator2
Mitsubishi Electric GT Designer2 Classic
Mitsubishi Electric GT Designer3 Version1 (GOT1000)
Mitsubishi Electric GT Designer3 Version1 (GOT2000)
Mitsubishi Electric GT SoftGOT1000
Mitsubishi Electric GT SoftGOT2000
Mitsubishi Electric GX Developer
Mitsubishi Electric GX LogViewer
Mitsubishi Electric GX Works2
Mitsubishi Electric GX Works3
Mitsubishi Electric M_CommDTM-IO-Link
Mitsubishi Electric MELFA-Works
Mitsubishi Electric MELSEC WinCPU Setting Utility
Mitsubishi Electric MELSOFT Complete Clean Up Tool
Mitsubishi Electric MELSOFT EM Software Development Kit
Mitsubishi Electric MELSOFT iQ AppPortal
Mitsubishi Electric iQ Works (MELSOFT Navigator)
Mitsubishi Electric MI Configurator
Mitsubishi Electric Motion Control Setting
Mitsubishi Electric Motorizer
Mitsubishi Electric MR Configurator2
Mitsubishi Electric MT Works2
Mitsubishi Electric MTConnect Data Collector
Mitsubishi Electric MX Component
Mitsubishi Electric MX MESInterface
Mitsubishi Electric MX MESInterface-R
Mitsubishi Electric MX Sheet
Mitsubishi Electric Network Interface Board CC IE Control Utility Firmware
Mitsubishi Electric Network Interface Board CC IE Field Utility
Mitsubishi Electric Network Interface Board CC-Link Ver.2 Utility
Mitsubishi Electric Network Interface Board MNETH Utility
Mitsubishi Electric Position Board Utility 2<=3.20
Mitsubishi Electric PX Developer
Mitsubishi Electric RT ToolBox2
Mitsubishi Electric RT ToolBox3
Mitsubishi Electric Setting/Monitoring tools for the C Controller module (SW3PVC-CCPU)
Mitsubishi Electric Setting/Monitoring tools for the C Controller module (SW4PVC-CCPU)
Mitsubishi Electric SLMP Data Collector
Mitsubishi Electric C Controller Interface Module Utility
Mitsubishi Electric Setting/Monitoring Tools for the C Controller Module
Mitsubishi Electric CC-Link IE Control Network Data Collector=1.00a
Mitsubishi Electric CC-Link IE Field Network Data Collector=1.00a
Mitsubishi Electric CC-Link IE TSN Data Collector=1.00a
Mitsubishi Electric CPU Module Logging Configuration Tool<=1.100e
Mitsubishi Electric CW Configurator<=1.010l
Mitsubishi Electric Data Transfer<=3.42u
Mitsubishi Electric EZSocket<=5.1
Mitsubishi Electric FR Configurator SW3
Mitsubishi Electric FR Configurator2 Firmware
Mitsubishi Electric GT Designer2 Classic
Mitsubishi Electric GT SoftGOT1000>=3.0<=3.200j
Mitsubishi Electric GT SoftGOT2000>=1.0<=1.241b
Mitsubishi Electric GX Developer<=8.504a
Mitsubishi Electric GX LogViewer<=1.100e
Mitsubishi Electric GX Works2<=1.601b
Mitsubishi Electric GX Works3<=1.063r
Mitsubishi Electric M Commdtm IO-Link
Mitsubishi Electric MELFA-Works<=4.4
Mitsubishi Electric MELSEC WinCPU Setting Utility
Mitsubishi Electric MELSOFT Complete Clean Up Tool<=1.06g
Mitsubishi Electric MELSOFT EM Software Development Kit
Mitsubishi Electric Melsoft IQ AppPortal<=1.17t
Mitsubishi Electric iQ Works (MELSOFT Navigator)<=2.74c
Mitsubishi Electric MI Configurator
Mitsubishi Electric Motion Control Setting<=1.005f
Mitsubishi Electric Motorizer<=1.005f
Mitsubishi Electric MR Configurator2<=1.125f
Mitsubishi Electric MT Works2<=1.167z
Mitsubishi Electric MTConnect Data Collector<=1.1.4.0
Mitsubishi Electric MX Component<=4.20w
Mitsubishi Electric MX MESInterface<=1.21x
Mitsubishi Electric MX MESInterface-R<=1.12n
Mitsubishi Electric MX Sheet<=2.15r
Mitsubishi Electric Position Board Utility 2
Mitsubishi Electric PX Developer<=1.53f
Mitsubishi Electric RT Toolbox2<=3.73b
Mitsubishi Electric RT Toolbox 3<=1.82l
Mitsubishi Electric Setting/Monitoring Tools for the C Controller Module
Mitsubishi Electric SLMP Data Collector<=1.04e
All of
Mitsubishi Electric GT Designer 3<=1.241b
Any of
Mitsubishi Electric GOT1000 Series GT10
Mitsubishi Electric GOT1000 Series GT11
Mitsubishi Electric GOT1000 Series GT12
Mitsubishielectric Got1000 Series Gt14 Firmware
Mitsubishi Electric GOT1000 Series GT15
Mitsubishi Electric GOT1000 Series GT16
Mitsubishi Electric GT21
Mitsubishi Electric GT SoftGOT1000
Mitsubishi Electric GT25
Mitsubishi Electric GT27
All of
Mitsubishi Electric Network Interface Board CC-Link Ver.2 Utility Firmware
Mitsubishi Electric Network Interface Board CC-Link Ver.2 Utility Firmware
All of
Mitsubishi Electric Network Interface Board CC IE Control Utility Firmware
Mitsubishi Electric Network Interface Board CC IE Control Utility Firmware
All of
Mitsubishi Electric Network Interface Board CC IE Field Utility Firmware
Mitsubishi Electric Network Interface Board CC IE Field Utility Firmware
All of
Mitsubishi Electric Network Interface Board MNETH Utility
Mitsubishi Electric Network Interface Board MNETH Utility
Mitsubishi Electric GT Designer 3<=1.241b
Mitsubishi Electric GOT1000 Series GT10
Mitsubishi Electric GOT1000 Series GT11
Mitsubishi Electric GOT1000 Series GT12
Mitsubishielectric Got1000 Series Gt14 Firmware
Mitsubishi Electric GOT1000 Series GT15
Mitsubishi Electric GOT1000 Series GT16
Mitsubishi Electric GT21
Mitsubishi Electric GT SoftGOT1000
Mitsubishi Electric GT25
Mitsubishi Electric GT27
Mitsubishi Electric Network Interface Board CC-Link Ver.2 Utility Firmware
Mitsubishi Electric Network Interface Board CC-Link Ver.2 Utility Firmware
Mitsubishi Electric Network Interface Board CC IE Control Utility Firmware
Mitsubishi Electric Network Interface Board CC IE Control Utility Firmware
Mitsubishi Electric Network Interface Board CC IE Field Utility Firmware
Mitsubishi Electric Network Interface Board CC IE Field Utility Firmware
Mitsubishi Electric Network Interface Board MNETH Utility
Mitsubishi Electric Network Interface Board MNETH Utility

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Parent vulnerabilities

(Appears in the following advisories)

Frequently Asked Questions

  • What is the severity of CVE-2020-14521?

    CVE-2020-14521 has been rated as a medium severity vulnerability.

  • How do I fix CVE-2020-14521?

    To fix CVE-2020-14521, update the affected Mitsubishi Electric software to the latest version recommended by the vendor.

  • What versions are affected by CVE-2020-14521?

    CVE-2020-14521 affects multiple Mitsubishi Electric Factory Automation engineering software products across various versions.

  • What are the potential impacts of CVE-2020-14521?

    The potential impacts of CVE-2020-14521 include unauthorized code execution, information modification, and denial-of-service conditions.

  • Is my Mitsubishi Electric software vulnerable to CVE-2020-14521?

    To determine if your Mitsubishi Electric software is vulnerable to CVE-2020-14521, check if you are using any of the affected software versions listed by the vendor.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203