ICSA-20-212-02: Mitsubishi electric cpu module logging configuration tool vulnerability
Affected Software
14 affected components
Mitsubishi Electric CPU Module Logging Configuration Tool, Versions 1.100E and prior
Mitsubishi Electric CW Configurator, Versions 1.010L and prior
Mitsubishi Electric Data Transfer, Versions 3.40S and prior
Mitsubishi Electric EZSocket, Versions 4.5 and prior
Mitsubishi Electric FR Configurator2, Versions 1.22Y and prior
Mitsubishi Electric GT Designer3 Version1 (GOT2000), Versions 1.235V and prior
Mitsubishi Electric GT SoftGOT1000 Version3, 3.200J and prior
Mitsubishi Electric GT SoftGOT2000 Version1, Versions 1.235V and prior
Mitsubishi Electric GX LogViewer, Versions 1.100E and prior
Mitsubishi Electric GX Works2, Versions 1.592S and prior
Mitsubishi Electric GX Works3, Versions 1.063R and prior
Mitsubishi Electric M_CommDTM-HART, Version 1.00A
Mitsubishi Electric M_CommDTM-IO-Link, Versions 1.03D and prior
Mitsubishi Electric MELFA-Works, versions 4.3 and prior
Event History
Feb 23, 2025
Advisory Published
01:15 PM
Frequently Asked Questions
1
What is the severity of ICSA-20-212-02?
The severity of ICSA-20-212-02 is rated as high due to potential unauthorized access and data manipulation.
2
How do I fix ICSA-20-212-02?
To fix ICSA-20-212-02, upgrade the affected software to the latest version as specified by Mitsubishi Electric.
3
What systems are affected by ICSA-20-212-02?
ICSA-20-212-02 affects various Mitsubishi Electric CPU modules and configuration tools as mentioned in the advisory.
4
What type of vulnerability is ICSA-20-212-02?
ICSA-20-212-02 involves improper input validation which can lead to remote code execution.
5
Are there any workarounds for ICSA-20-212-02?
No specific workarounds are recommended for ICSA-20-212-02; applying the patches or upgrades is the best course of action.