ICSA-20-212-04: Mitsubishi electric c controller interface module utility vulnerability
Affected Software
47 affected components
Mitsubishi Electric C Controller Interface Module Utility, Versions 2.00 and prior
Mitsubishi Electric CC-Link IE Control Network Data Collector, Version 1.00A
Mitsubishi Electric CC-Link IE Field Network Data Collector, Version 1.00A
Mitsubishi Electric CC-Link IE TSN Data Collector, Version 1.00A
Mitsubishi Electric CPU Module Logging Configuration Tool, Versions 1.100E and prior
Mitsubishi Electric CW Configurator, Versions 1.010L and prior
Mitsubishi Electric Data Transfer, Versions 3.42U and prior
Mitsubishi Electric EZSocket, version 5.1 and prior
Mitsubishi Electric FR Configurator SW3, All versions
Mitsubishi Electric FR Configurator2: Versions 1.26C and prior
Mitsubishi Electric GT Designer2 Classic, all versions
Mitsubishi Electric GT Designer3 Version1 (GOT1000), Versions 1.241B and prior
Mitsubishi Electric GT Designer3 Version1 (GOT2000), Versions 1.241B and prior
Mitsubishi Electric GT SoftGOT1000 Version3, Versions 3.200J and prior
Mitsubishi Electric GT SoftGOT2000 Version1, Versions 1.241B and prior
Mitsubishi Electric GX Developer, Versions 8.504A and prior
Mitsubishi Electric GX LogViewer, Versions 1.100E and prior
Mitsubishi Electric GX Works2, Versions 1.601B and prior
Mitsubishi Electric GX Works3, Versions 1.063R and prior
Mitsubishi Electric M_CommDTM-IO-Link, Versions 1.03D and prior
Mitsubishi Electric MELFA-Works: Version 4.4 and prior
Mitsubishi Electric MELSEC WinCPU Setting Utility, All versions
Mitsubishi Electric MELSOFT Complete Clean Up Tool, Versions 1.06G and prior
Mitsubishi Electric MELSOFT EM Software Development Kit, Versions 1.015R and prior
Mitsubishi Electric MELSOFT iQ AppPortal, 1.17T and prior
Mitsubishi Electric MELSOFT Navigator, Versions 2.74C and prior
Mitsubishi Electric MI Configurator, Version 1.004E and prior
Mitsubishi Electric Motion Control Setting, Versions 1.005F and prior
Mitsubishi Electric Motorizer, Versions 1.005F and prior
Mitsubishi Electric MR Configurator2, Version 1.125F and prior
Mitsubishi Electric MT Works2, Version 1.167Z and prior
Mitsubishi Electric MTConnect Data Collector, Version 1.1.4.0 and prior
Mitsubishi Electric MX Component, Version 4.20W and prior
Mitsubishi Electric MX MESInterface, Versions 1.21X and prior
Mitsubishi Electric MX MESInterface-R, Versions 1.12N and prior
Mitsubishi Electric MX Sheet, Version 2.15R and prior
Mitsubishi Electric Network Interface Board CC IE Control Utility, Versions 1.29F and prior
Mitsubishi Electric Network Interface Board CC IE Field Utility, Versions 1.16S and prior
Mitsubishi Electric Network Interface Board CC-Link Ver.2 Utility, Versions 1.23Z and prior
Mitsubishi Electric Network Interface Board MNETH Utility, Versions 34L and prior
Mitsubishi Electric Position Board Utility 2<=3.20
Mitsubishi Electric PX Developer, version 1.53F and prior
Mitsubishi Electric RT ToolBox2: Version 3.73B and prior
Mitsubishi Electric RT ToolBox3: Version 1.82L and prior
Mitsubishi Electric Setting/Monitoring tools for the C Controller module (SW3PVC-CCPU), Version 3.13P and prior
Mitsubishi Electric Setting/Monitoring tools for the C Controller module (SW4PVC-CCPU), Version 4.12N and prior
Mitsubishi Electric SLMP Data Collector, Version 1.04E and prior
Event History
Feb 26, 2025
Advisory Published
02:07 AM
Frequently Asked Questions
1
What is the severity of ICSA-20-212-04?
The severity of ICSA-20-212-04 is rated as high due to the potential for remote code execution.
2
How do I fix ICSA-20-212-04?
To fix ICSA-20-212-04, update to the latest version of affected Mitsubishi Electric software as specified in the advisory.
3
What software is affected by ICSA-20-212-04?
ICSA-20-212-04 affects several Mitsubishi Electric software products, including versions of the C Controller Interface Module Utility and various data collectors.
4
What vulnerabilities are associated with ICSA-20-212-04?
ICSA-20-212-04 concerns vulnerabilities that may allow unauthorized access and remote code execution in affected Mitsubishi Electric software.
5
Are there any mitigations for ICSA-20-212-04?
While the primary mitigation is to apply software updates, you should also ensure network segregation of affected devices as an additional risk reduction strategy.