CVE-2020-14523: Mitsubishi Electric Factory Automation Products Path Traversal
Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-14523?
The severity of CVE-2020-14523 is critical with a CVSS score of 9.8.
Which Mitsubishi Electric Factory Automation products are affected by CVE-2020-14523?
Multiple Mitsubishi Electric Factory Automation products are affected, including CW Configurator, FR Configurator2, GX Works2, GX Works3, IU Configuration Tool, IU Developer2, Melsoft IQ Appportal, Melsoft Navigator, MI Configurator, MR Configurator2, MT Works2, MX Component, RT Toolbox3, Rd78g4 Firmware, Rd78g8 Firmware, Rd78g16 Firmware, Rd78g32 Firmware, Rd78g64 Firmware, Rd78ghv Firmware, and Rd78ghw Firmware.
What is the vulnerability of CVE-2020-14523?
CVE-2020-14523 allows an attacker to execute arbitrary code.
Are there any available fixes for CVE-2020-14523?
Mitsubishi Electric has released a security update to address the vulnerability. Please refer to their official advisory for more information.
Where can I find more information about CVE-2020-14523?
You can find more information about CVE-2020-14523 from the Japan Vulnerability Notes (JVN) website, US-CERT advisories, and the official Mitsubishi Electric PSIRT advisory.