CWE
22
Advisory Published
Updated

CVE-2020-14523: Mitsubishi Electric Factory Automation Products Path Traversal

First published: Fri Feb 11 2022(Updated: )

Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.

Credit: ics-cert@hq.dhs.gov

Affected SoftwareAffected VersionHow to fix
Mitsubishielectric Cw Configurator<=1.010l
Mitsubishielectric Fr Configurator2<=1.22y
Mitsubishielectric Gx Works2<=1.595v
Mitsubishielectric Gx Works3<=1.063r
Mitsubishielectric Iu Configuration Tool<=1.04
Mitsubishielectric Iu Developer2<=1.08
Mitsubishielectric Melsoft Iq Appportal<=1.17t
Mitsubishielectric Melsoft Navigator<=2.70y
Mitsubishielectric Mi Configurator
Mitsubishielectric Mr Configurator2<=1.110q
Mitsubishielectric Mt Works2<=1.156n
Mitsubishielectric Mx Component<=4.20w
Mitsubishielectric Rt Toolbox3<=1.70y
Mitsubishielectric Rd78g4 Firmware<=10
Mitsubishielectric Rd78g4
Mitsubishielectric Rd78g8 Firmware<=10
Mitsubishielectric Rd78g8
Mitsubishielectric Rd78g16 Firmware<=10
Mitsubishielectric Rd78g16
Mitsubishielectric Rd78g32 Firmware<=10
Mitsubishielectric Rd78g32
Mitsubishielectric Rd78g64 Firmware<=10
Mitsubishielectric Rd78g64
Mitsubishielectric Rd78ghv Firmware<=10
Mitsubishielectric Rd78ghv
Mitsubishielectric Rd78ghw Firmware<=10
Mitsubishielectric Rd78ghw
Mitsubishi Electric MELSOFT iQ AppPortal, Version 1.17T and prior
Mitsubishi Electric MELSOFT Navigator, 2.70Y and prior

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Parent vulnerabilities

(Appears in the following advisories)

Frequently Asked Questions

  • What is the severity of CVE-2020-14523?

    The severity of CVE-2020-14523 is critical with a CVSS score of 9.8.

  • Which Mitsubishi Electric Factory Automation products are affected by CVE-2020-14523?

    Multiple Mitsubishi Electric Factory Automation products are affected, including CW Configurator, FR Configurator2, GX Works2, GX Works3, IU Configuration Tool, IU Developer2, Melsoft IQ Appportal, Melsoft Navigator, MI Configurator, MR Configurator2, MT Works2, MX Component, RT Toolbox3, Rd78g4 Firmware, Rd78g8 Firmware, Rd78g16 Firmware, Rd78g32 Firmware, Rd78g64 Firmware, Rd78ghv Firmware, and Rd78ghw Firmware.

  • What is the vulnerability of CVE-2020-14523?

    CVE-2020-14523 allows an attacker to execute arbitrary code.

  • Are there any available fixes for CVE-2020-14523?

    Mitsubishi Electric has released a security update to address the vulnerability. Please refer to their official advisory for more information.

  • Where can I find more information about CVE-2020-14523?

    You can find more information about CVE-2020-14523 from the Japan Vulnerability Notes (JVN) website, US-CERT advisories, and the official Mitsubishi Electric PSIRT advisory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203