CWE
22
Advisory Published
Updated

CVE-2020-14523: Mitsubishi Electric Factory Automation Products Path Traversal

First published: Fri Feb 11 2022(Updated: )

Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.

Credit: ics-cert@hq.dhs.gov

Affected SoftwareAffected VersionHow to fix
Mitsubishi Electric CW Configurator
Mitsubishi Electric FR Configurator2
Mitsubishi Electric GX Works2
Mitsubishi Electric GX Works3
Mitsubishi Electric MELSEC iQ-R Series Motion Module
Mitsubishi Electric MELSOFT iQ AppPortal
Mitsubishi Electric iQ Works (MELSOFT Navigator)
Mitsubishi Electric CW Configurator<=1.010l
Mitsubishi Electric FR Configurator2 Firmware<=1.22y
Mitsubishi Electric GX Works2<=1.595v
Mitsubishi Electric GX Works3<=1.063r
Mitsubishi Electric Iu Configuration Tool<=1.04
Mitsubishi Electric Iu Developer2<=1.08
Mitsubishi Electric Melsoft IQ AppPortal<=1.17t
Mitsubishi Electric iQ Works (MELSOFT Navigator)<=2.70y
Mitsubishi Electric MI Configurator
Mitsubishi Electric MR Configurator2<=1.110q
Mitsubishi Electric MT Works2<=1.156n
Mitsubishi Electric MX Component<=4.20w
Mitsubishi Electric RT Toolbox 3<=1.70y
Mitsubishi Electric RD78G4<=10
Mitsubishi Electric RD78G4
Mitsubishi Electric RD78G8<=10
Mitsubishi Electric RD78G8
Mitsubishi Electric RD78G16<=10
Mitsubishi Electric RD78G16
Mitsubishi Electric RD78G32 Firmware<=10
Mitsubishi Electric RD78G32
Mitsubishi Electric RD78G64<=10
Mitsubishielectric Rd78g64 Firmware
Mitsubishielectric Rd78ghv Firmware<=10
Mitsubishielectric Rd78ghv Firmware
Mitsubishi Electric RD78GHW<=10
Mitsubishi Electric RD78GHW

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Parent vulnerabilities

(Appears in the following advisories)

Frequently Asked Questions

  • What is the severity of CVE-2020-14523?

    The severity of CVE-2020-14523 is critical with a CVSS score of 9.8.

  • Which Mitsubishi Electric Factory Automation products are affected by CVE-2020-14523?

    Multiple Mitsubishi Electric Factory Automation products are affected, including CW Configurator, FR Configurator2, GX Works2, GX Works3, IU Configuration Tool, IU Developer2, Melsoft IQ Appportal, Melsoft Navigator, MI Configurator, MR Configurator2, MT Works2, MX Component, RT Toolbox3, Rd78g4 Firmware, Rd78g8 Firmware, Rd78g16 Firmware, Rd78g32 Firmware, Rd78g64 Firmware, Rd78ghv Firmware, and Rd78ghw Firmware.

  • What is the vulnerability of CVE-2020-14523?

    CVE-2020-14523 allows an attacker to execute arbitrary code.

  • Are there any available fixes for CVE-2020-14523?

    Mitsubishi Electric has released a security update to address the vulnerability. Please refer to their official advisory for more information.

  • Where can I find more information about CVE-2020-14523?

    You can find more information about CVE-2020-14523 from the Japan Vulnerability Notes (JVN) website, US-CERT advisories, and the official Mitsubishi Electric PSIRT advisory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203