Vulnerability Description
Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mitsubishielectric | Cw Configurator | <= 1.010l |
| Mitsubishielectric | Fr Configurator2 | <= 1.22y |
| Mitsubishielectric | Gx Works2 | <= 1.595v |
| Mitsubishielectric | Gx Works3 | <= 1.063r |
| Mitsubishielectric | Iu Configuration Tool | <= 1.04 |
| Mitsubishielectric | Iu Developer2 | <= 1.08 |
| Mitsubishielectric | Melsoft Iq Appportal | <= 1.17t |
| Mitsubishielectric | Melsoft Navigator | <= 2.70y |
| Mitsubishielectric | Mi Configurator | All versions |
| Mitsubishielectric | Mr Configurator2 | <= 1.110q |
| Mitsubishielectric | Mt Works2 | <= 1.156n |
| Mitsubishielectric | Mx Component | <= 4.20w |
| Mitsubishielectric | Rt Toolbox3 | <= 1.70y |
| Mitsubishielectric | Rd78G4 Firmware | <= 10 |
| Mitsubishielectric | Rd78G4 | - |
| Mitsubishielectric | Rd78G8 Firmware | <= 10 |
| Mitsubishielectric | Rd78G8 | - |
| Mitsubishielectric | Rd78G16 Firmware | <= 10 |
| Mitsubishielectric | Rd78G16 | - |
| Mitsubishielectric | Rd78G32 Firmware | <= 10 |
Related Weaknesses (CWE)
References
- https://jvn.jp/vu/JVNVU90224831/Third Party Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-03PatchThird Party AdvisoryUS Government Resource
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-008_en.pdfVendor Advisory
- https://jvn.jp/vu/JVNVU90224831/Third Party Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-03PatchThird Party AdvisoryUS Government Resource
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-008_en.pdfVendor Advisory
FAQ
What is CVE-2020-14523?
CVE-2020-14523 is a vulnerability with a CVSS score of 8.3 (HIGH). Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.
How severe is CVE-2020-14523?
CVE-2020-14523 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-14523?
Check the references section above for vendor advisories and patch information. Affected products include: Mitsubishielectric Cw Configurator, Mitsubishielectric Fr Configurator2, Mitsubishielectric Gx Works2, Mitsubishielectric Gx Works3, Mitsubishielectric Iu Configuration Tool.