CVE-2020-14523: Mitsubishi Electric Factory Automation Products Path Traversal

Published Feb 11, 2022
·
Updated

Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.

Affected Software

34 affected components
Mitsubishi Electric CW Configurator,Versions 1.010L and prior
Mitsubishi Electric FR Configurator2, Versions 1.22Y and prior
Mitsubishi Electric GX Works2, Versions 1.595V and prior
Mitsubishi Electric GX Works3, Versions 1.063R and prior
Mitsubishi Electric MELSEC iQ-R Series Motion Module, Versions 10 and prior
Mitsubishi Electric MELSOFT iQ AppPortal, Version 1.17T and prior
Mitsubishi Electric MELSOFT Navigator, 2.70Y and prior
Mitsubishielectric Cw Configurator<=1.010l
Mitsubishielectric Fr Configurator2<=1.22y
Mitsubishielectric Gx Works2<=1.595v
Mitsubishielectric Gx Works3<=1.063r
Mitsubishielectric Iu Configuration Tool<=1.04
Mitsubishielectric Iu Developer2<=1.08
Mitsubishielectric Melsoft Iq Appportal<=1.17t
Mitsubishielectric Melsoft Navigator<=2.70y
Mitsubishielectric Mi Configurator
Mitsubishielectric Mr Configurator2<=1.110q
Mitsubishielectric Mt Works2<=1.156n
Mitsubishielectric Mx Component<=4.20w
Mitsubishielectric Rt Toolbox3<=1.70y
Mitsubishielectric Rd78g4 Firmware<=10
Mitsubishielectric Rd78g4
Mitsubishielectric Rd78g8 Firmware<=10
Mitsubishielectric Rd78g8
Mitsubishielectric Rd78g16 Firmware<=10
Mitsubishielectric Rd78g16
Mitsubishielectric Rd78g32 Firmware<=10
Mitsubishielectric Rd78g32
Mitsubishielectric Rd78g64 Firmware<=10
Mitsubishielectric Rd78g64
Mitsubishielectric Rd78ghv Firmware<=10
Mitsubishielectric Rd78ghv
Mitsubishielectric Rd78ghw Firmware<=10
Mitsubishielectric Rd78ghw

Event History

Feb 11, 2022
CVE Published
via MITRE·05:40 PM
Data Sourced
via MITRE·05:40 PM
DescriptionSeverityWeakness

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2020-14523?

The severity of CVE-2020-14523 is critical with a CVSS score of 9.8.

2

Which Mitsubishi Electric Factory Automation products are affected by CVE-2020-14523?

Multiple Mitsubishi Electric Factory Automation products are affected, including CW Configurator, FR Configurator2, GX Works2, GX Works3, IU Configuration Tool, IU Developer2, Melsoft IQ Appportal, Melsoft Navigator, MI Configurator, MR Configurator2, MT Works2, MX Component, RT Toolbox3, Rd78g4 Firmware, Rd78g8 Firmware, Rd78g16 Firmware, Rd78g32 Firmware, Rd78g64 Firmware, Rd78ghv Firmware, and Rd78ghw Firmware.

3

What is the vulnerability of CVE-2020-14523?

CVE-2020-14523 allows an attacker to execute arbitrary code.

4

Are there any available fixes for CVE-2020-14523?

Mitsubishi Electric has released a security update to address the vulnerability. Please refer to their official advisory for more information.

5

Where can I find more information about CVE-2020-14523?

You can find more information about CVE-2020-14523 from the Japan Vulnerability Notes (JVN) website, US-CERT advisories, and the official Mitsubishi Electric PSIRT advisory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203