CVE-2021-20607: Integer Underflow
Integer Underflow vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior, Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior and Mitsubishi Electric EZSocket versions 5.4 and prior allows an attacker to cause a DoS condition in the software by getting a user to open malicious project file specially crafted by an attacker.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20607?
The severity of CVE-2021-20607 is medium with a severity value of 5.5.
Which software versions are affected by CVE-2021-20607?
Mitsubishi Electric GX Works2 versions 1.606G and prior, Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior, and Mitsubishi Electric EZSocket versions 5.4 and prior are affected by CVE-2021-20607.
How does CVE-2021-20607 vulnerability occur?
CVE-2021-20607 is an integer underflow vulnerability that allows an attacker to cause a DoS condition in the affected software by getting a user to open malicious files.
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-20607?
The Common Weakness Enumeration (CWE) ID for CVE-2021-20607 is CWE-191.
Where can I find more information about CVE-2021-20607?
You can find more information about CVE-2021-20607 at the following references: [link1](https://jvn.jp/vu/JVNVU93817405/index.html), [link2](https://us-cert.cisa.gov/ics/advisories/icsa-21-350-05), [link3](https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-021_en.pdf).