CVE-2021-20606: Medium severity mitsubishi electric gx works2 vulnerability
Out-of-bounds Read vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior, Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior and Mitsubishi Electric EZSocket versions 5.4 and prior allows an attacker to cause a DoS condition in the software by getting a user to open malicious project file specially crafted by an attacker.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-20606?
CVE-2021-20606 is an out-of-bounds read vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior, Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior, and Mitsubishi Electric EZSocket versions 5.4 and prior.
What is the severity of CVE-2021-20606?
CVE-2021-20606 has a severity level of 5.5 (medium).
How does CVE-2021-20606 affect Mitsubishi Electric GX Works2?
CVE-2021-20606 affects Mitsubishi Electric GX Works2 versions 1.606G and prior.
How does CVE-2021-20606 affect Mitsubishi Electric MELSOFT Navigator?
CVE-2021-20606 affects Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior.
How does CVE-2021-20606 affect Mitsubishi Electric EZSocket?
CVE-2021-20606 affects Mitsubishi Electric EZSocket versions 5.4 and prior.
How can CVE-2021-20606 be exploited?
CVE-2021-20606 can be exploited by getting a user to open manipulated project files or configuration files, leading to a denial-of-service (DoS) condition in the affected software.
Are there any fixes available for CVE-2021-20606?
Yes, Mitsubishi Electric has provided a security advisory with mitigation details and recommended software updates to address CVE-2021-20606.