First published: Tue Jun 23 2020(Updated: )
Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows cleartext transmission of sensitive information between CPU modules and GX Works3 and/or GX Works2 via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishi Electric Melsec IQ-R Firmware | ||
Mitsubishi Electric Melsec Iq-r | ||
Mitsubishi Electric MELSEC-iQ-F | ||
Mitsubishi Electric MELSEC-iQ-F | ||
Mitsubishi Electric Melsec-Q Firmware | ||
Mitsubishi Electric Melsec-Q | ||
Mitsubishi Electric Melsec-L Firmware | ||
Mitsubishi Electric Melsec-L Firmware | ||
Mitsubishi Electric Melsec-FX Firmware | ||
Mitsubishi Electric Melsec-FX Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5594 is classified as a medium severity vulnerability due to the cleartext transmission of sensitive information.
To mitigate CVE-2020-5594, ensure secure transmission methods are implemented between the CPU modules and GX Works3 or GX Works2.
CVE-2020-5594 affects Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules.
CVE-2020-5594 potentially exposes sensitive information transmitted in cleartext between control modules and software.
All versions of the affected Mitsubishi Electric MELSEC firmware are compromised by CVE-2020-5594.