CVE-2020-5602: XEE
Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX LogViewer Ver. 1.96A and earlier, GX Works2 Ver. 1.586L and earlier, GX Works3 Ver. 1.058L and earlier, MCommDTM-HART Ver. 1.00A, MCommDTM-IO-Link Ver. 1.02C and earlier, MELFA-Works Ver. 4.3 and earlier, MELSEC-L Flexible High-Speed I/O Control Module Configuration Tool Ver.1.004E and earlier, MELSOFT FieldDeviceConfigurator Ver. 1.03D and earlier, MELSOFT iQ AppPortal Ver. 1.11M and earlier, MELSOFT Navigator Ver. 2.58L and earlier, MI Configurator Ver. 1.003D and earlier, Motion Control Setting Ver. 1.005F and earlier, MR Configurator2 Ver. 1.72A and earlier, MT Works2 Ver. 1.156N and earlier, RT ToolBox2 Ver. 3.72A and earlier, and RT ToolBox3 Ver. 1.50C and earlier) allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5602?
The severity of CVE-2020-5602 is high with a CVSS score of 7.5.
Which software versions are affected by CVE-2020-5602?
The affected software versions for CVE-2020-5602 include Mitsubishi Electoric FA Engineering Software CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX LogViewer Ver. 1.96A and earlier.
Are there any known fixes for CVE-2020-5602?
Yes, please refer to the Mitsubishi Electric PSIRT advisory for information on available fixes for CVE-2020-5602.
Can you provide more information about CVE-2020-5602?
CVE-2020-5602 is a vulnerability that allows an attacker to execute arbitrary code or cause a denial of service on affected Mitsubishi Electric FA Engineering Software.
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-5602?
The Common Weakness Enumeration (CWE) ID for CVE-2020-5602 is 611.