HIGH · 8.3

CVE-2020-14496

Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and ex...

Vulnerability Description

Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed, tampered with, and/or destroyed.

CVSS Score

8.3

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
MitsubishielectricCpu Module Logging Configuration Tool< 1.106k
MitsubishielectricCw Configurator< 1.011m
MitsubishielectricData Transfer< 3.41t
MitsubishielectricEm Configurator< 1.015r
MitsubishielectricEzsocket< 4.6
MitsubishielectricFr Configurator2< 1.23z
MitsubishielectricGt Designer3< 1.236w
MitsubishielectricGt Softgot1000< 3.245f
MitsubishielectricGt Softgot2000< 1.236w
MitsubishielectricGx Logviewer< 1.106k
MitsubishielectricGx Works2< 1.595v
MitsubishielectricGx Works3< 1.065t
MitsubishielectricM Commdtm-Hart< 1.01b
MitsubishielectricM Commdtm-Io-Link< 1.04e
MitsubishielectricMelfa-Works< 4.4
MitsubishielectricMelsoft Fielddeviceconfigurator< 1.04e
MitsubishielectricMelsoft Navigator< 2.70y
MitsubishielectricMh11 Settingtool Version2< 2.003d
MitsubishielectricMotorizer< 1.010l
MitsubishielectricMr Configurator2< 1.106l

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-14496?

CVE-2020-14496 is a vulnerability with a CVSS score of 8.3 (HIGH). Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and ex...

How severe is CVE-2020-14496?

CVE-2020-14496 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-14496?

Check the references section above for vendor advisories and patch information. Affected products include: Mitsubishielectric Cpu Module Logging Configuration Tool, Mitsubishielectric Cw Configurator, Mitsubishielectric Data Transfer, Mitsubishielectric Em Configurator, Mitsubishielectric Ezsocket.