CVE-2020-14523
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.
Affected (20)
Products: Mitsubishielectric: Cw Configurator, Fr Configurator2, Gx Works2, Gx Works3, Iu Configuration Tool, Iu Developer2, Melsoft Iq Appportal, Melsoft Navigator, Mi Configurator, Mr Configurator2, Mt Works2, Mx Component, Rt Toolbox3, Rd78g4 Firmware, Rd78g8 Firmware, Rd78g16 Firmware, Rd78g32 Firmware, Rd78g64 Firmware, Rd78ghv Firmware, Rd78ghw Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.010l | |
| Up to 1.22y | |
| Up to 1.595v | |
| Up to 1.063r | |
| Up to 1.04 | |
| Up to 1.08 | |
| Up to 1.17t | |
| Up to 2.70y | |
| All versions | |
| Up to 1.110q | |
| Up to 1.156n | |
| Up to 4.20w | |
| Up to 1.70y |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishielectric Rd78g4 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishielectric Rd78g8 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishielectric Rd78g16 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishielectric Rd78g32 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishielectric Rd78g64 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishielectric Rd78ghv | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishielectric Rd78ghw | All versions |
References (6)
Source: ics-cert@hq.dhs.gov
PatchThird Party AdvisoryUS Government Resource
Source: ics-cert@hq.dhs.gov
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.