HIGH · 7.5

CVE-2020-5603

Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, ...

Vulnerability Description

Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX LogViewer Ver. 1.96A and earlier, GX Works2 Ver. 1.586L and earlier, GX Works3 Ver. 1.058L and earlier, M_CommDTM-HART Ver. 1.00A, M_CommDTM-IO-Link Ver. 1.02C and earlier, MELFA-Works Ver. 4.3 and earlier, MELSEC-L Flexible High-Speed I/O Control Module Configuration Tool Ver.1.004E and earlier, MELSOFT FieldDeviceConfigurator Ver. 1.03D and earlier, MELSOFT iQ AppPortal Ver. 1.11M and earlier, MELSOFT Navigator Ver. 2.58L and earlier, MI Configurator Ver. 1.003D and earlier, Motion Control Setting Ver. 1.005F and earlier, MR Configurator2 Ver. 1.72A and earlier, MT Works2 Ver. 1.156N and earlier, RT ToolBox2 Ver. 3.72A and earlier, and RT ToolBox3 Ver. 1.50C and earlier) allows an attacker to cause a denial of service (DoS) condition attacks via unspecified vectors.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
MitsubishielectricCpu Module Logging Configuration Tool<= 1.94y
MitsubishielectricCw Configurator<= 1.010l
MitsubishielectricEm Configurator<= 1.010l
MitsubishielectricGt Designer3<= 1.221f
MitsubishielectricGx Logviewer<= 1.100e
MitsubishielectricGx Works2<= 1.590q
MitsubishielectricGx Works3<= 1.060n
MitsubishielectricM Commdtm-Hart<= 1.01b
MitsubishielectricM Commdtm-Io-Link<= 1.03d
MitsubishielectricMelfa-Works<= 4.4
MitsubishielectricMelsec-L Flexible High-Speed I\/O Control Module Configuration Tool<= 1.005f
MitsubishielectricMelsoft Fielddeviceconfigurator<= 1.04e
MitsubishielectricMelsoft Iq Appportal<= 1.14q
MitsubishielectricMelsoft Navigator<= 2.62q
MitsubishielectricMi Configurator<= 1.004e
MitsubishielectricMotion Control Setting<= 1.006g
MitsubishielectricMr Configurator2<= 1.100e
MitsubishielectricMt Works2<= 1.160s
MitsubishielectricRt Toolbox2<= 3.73b
MitsubishielectricRt Toolbox3<= 1.60n

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-5603?

CVE-2020-5603 is a vulnerability with a CVSS score of 7.5 (HIGH). Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, ...

How severe is CVE-2020-5603?

CVE-2020-5603 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-5603?

Check the references section above for vendor advisories and patch information. Affected products include: Mitsubishielectric Cpu Module Logging Configuration Tool, Mitsubishielectric Cw Configurator, Mitsubishielectric Em Configurator, Mitsubishielectric Gt Designer3, Mitsubishielectric Gx Logviewer.