HIGH · 8.3

CVE-2020-14521

Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, mo...

Vulnerability Description

Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.

CVSS Score

8.3

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
MitsubishielectricC Controller Interface Module UtilityAll versions
MitsubishielectricC Controller Module Setting And Monitoring ToolAll versions
MitsubishielectricCc-Link Ie Control Network Data Collector1.00a
MitsubishielectricCc-Link Ie Field Network Data Collector1.00a
MitsubishielectricCc-Link Ie Tsn Data Collector1.00a
MitsubishielectricCpu Module Logging Configuration Tool<= 1.100e
MitsubishielectricCw Configurator<= 1.010l
MitsubishielectricData Transfer<= 3.42u
MitsubishielectricEzsocket<= 5.1
MitsubishielectricFr Configurator Sw3All versions
MitsubishielectricFr Configurator2All versions
MitsubishielectricGt Designer2 ClassicAll versions
MitsubishielectricGt Softgot1000>= 3.0, <= 3.200j
MitsubishielectricGt Softgot2000>= 1.0, <= 1.241b
MitsubishielectricGx Developer<= 8.504a
MitsubishielectricGx Logviewer<= 1.100e
MitsubishielectricGx Works2<= 1.601b
MitsubishielectricGx Works3<= 1.063r
MitsubishielectricM Commdtm-Io-LinkAll versions
MitsubishielectricMelfa-Works<= 4.4

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-14521?

CVE-2020-14521 is a vulnerability with a CVSS score of 8.3 (HIGH). Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, mo...

How severe is CVE-2020-14521?

CVE-2020-14521 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-14521?

Check the references section above for vendor advisories and patch information. Affected products include: Mitsubishielectric C Controller Interface Module Utility, Mitsubishielectric C Controller Module Setting And Monitoring Tool, Mitsubishielectric Cc-Link Ie Control Network Data Collector, Mitsubishielectric Cc-Link Ie Field Network Data Collector, Mitsubishielectric Cc-Link Ie Tsn Data Collector.