First published: Fri Dec 17 2021(Updated: )
Integer Underflow vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior, Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior and Mitsubishi Electric EZSocket versions 5.4 and prior allows an attacker to cause a DoS condition in the software by getting a user to open malicious project file specially crafted by an attacker.
Credit: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishielectric Ezsocket | <=5.4 | |
Mitsubishielectric Gx Works2 | <=1.606g | |
Mitsubishielectric Melsoft Navigator | ||
Mitsubishi Electric GX Works2: Versions 1.606G and prior | ||
Mitsubishi Electric MELSOFT Navigator: Versions 2.84N and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-20607 is medium with a severity value of 5.5.
Mitsubishi Electric GX Works2 versions 1.606G and prior, Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior, and Mitsubishi Electric EZSocket versions 5.4 and prior are affected by CVE-2021-20607.
CVE-2021-20607 is an integer underflow vulnerability that allows an attacker to cause a DoS condition in the affected software by getting a user to open malicious files.
The Common Weakness Enumeration (CWE) ID for CVE-2021-20607 is CWE-191.
You can find more information about CVE-2021-20607 at the following references: [link1](https://jvn.jp/vu/JVNVU93817405/index.html), [link2](https://us-cert.cisa.gov/ics/advisories/icsa-21-350-05), [link3](https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-021_en.pdf).