← Back

CVE-2021-20587

nvd nist
Published: Feb 19, 2021Modified: Jun 13, 2025

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3 all versions, FR Configurator2 versions 1.24A and prior, GT Designer3 Version1(GOT1000) versions 1.250L and prior, GT Designer3 Version1(GOT2000) versions 1.250L and prior, GT SoftGOT1000 Version3 versions 3.245F and prior, GT SoftGOT2000 Version1 versions 1.250L and prior, GX Configurator-DP versions 7.14Q and prior, GX Configurator-QP all versions, GX Developer versions 8.506C and prior, GX Explorer all versions, GX IEC Developer all versions, GX LogViewer versions 1.115U and prior, GX RemoteService-I all versions, GX Works2 versions 1.597X and prior, GX Works3 versions 1.070Y and prior, iQ Monozukuri ANDON (Data Transfer) versions 1.003D and prior, iQ Monozukuri Process Remote Monitoring (Data Transfer) versions 1.002C and prior, M_CommDTM-HART all versions, M_CommDTM-IO-Link versions 1.03D and prior, MELFA-Works versions 4.4 and prior, MELSEC WinCPU Setting Utility all versions, MELSOFT EM Software Development Kit (EM Configurator) versions 1.015R and prior, MELSOFT Navigator versions 2.74C and prior, MH11 SettingTool Version2 versions 2.004E and prior, MI Configurator versions 1.004E and prior, MT Works2 versions 1.167Z and prior, MX Component versions 5.001B and prior, Network Interface Board CC IE Control utility versions 1.29F and prior, Network Interface Board CC IE Field Utility versions 1.16S and prior, Network Interface Board CC-Link Ver.2 Utility versions 1.23Z and prior, Network Interface Board MNETH utility versions 34L and prior, PX Developer versions 1.53F and prior, RT ToolBox2 versions 3.73B and prior, RT ToolBox3 versions 1.82L and prior, Setting/monitoring tools for the C Controller module (SW4PVC-CCPU) versions 4.12N and prior, and SLMP Data Collector versions 1.04E and prior) allows a remote unauthenticated attacker to cause a DoS condition on the software products, and possibly to execute a malicious code on the personal computer running the software products although it has not been reproduced, by spoofing MELSEC, GOT or FREQROL and returning crafted reply packets.

Affected (41)

Products: Mitsubishielectric: C Controller Module Setting And Monitoring Tool, Cpu Module Logging Configuration Tool, Cw Configurator, Data Transfer, Ezsocket, Fr Configurator, Fr Configurator2, Fr Configurator Sw3, Gt Designer3, Gt Softgot1000, Gt Softgot2000, Gx Configurator Dp, Gx Configurator Qp, Gx Developer, Gx Explorer, Gx Iec Developer, Gx Logviewer, Gx Remoteservice I, Gx Works2, Gx Works3, Iq Monozukuri Andon, Iq Monozukuri Process Remote Monitoring, M Commdtm Hart, M Commdtm Io Link, Melfa Works, Melsec Wincpu Setting Utility, Melsoft Em Software Development Kit, Melsoft Navigator, Mh11 Settingtool Version2, Mi Configurator, Mt Works2, Mx Component, Network Interface Board Cc Link, Network Interface Board Cc Ie Control Utility, Network Interface Board Cc Ie Field Utility, Network Interface Board Mneth Utility, Px Developer, Rt Toolbox2, Rt Toolbox3, Setting/monitoring Tools For The C Controller Module, Slmp Data Collector
Cw Configurator
Data Transfer
Ezsocket
Fr Configurator
Fr Configurator2
Fr Configurator Sw3
Gt Designer3
Gt Softgot1000
Gt Softgot2000
Gx Configurator Dp
Gx Configurator Qp
Gx Developer
Gx Explorer
Gx Iec Developer
Gx Logviewer
Gx Remoteservice I
Gx Works2
Gx Works3
Iq Monozukuri Andon
M Commdtm Hart
M Commdtm Io Link
Melfa Works
Melsec Wincpu Setting Utility
Melsoft Navigator
Mh11 Settingtool Version2
Mi Configurator
Mt Works2
Mx Component
Network Interface Board Cc Link
Px Developer
Rt Toolbox2
Rt Toolbox3
Slmp Data Collector
Configuration A
41 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Up to 1.112r
Up to 1.011m
Up to 3.44w
All versions
All versions
Up to 1.24a
All versions
Up to 1.250l
Up to 3.245f
Up to 1.250l
Up to 7.14q
All versions
Up to 8.506c
All versions
All versions
Up to 1.115u
All versions
Up to 1.597x
Up to 1.070y
All versions
All versions
All versions
All versions
Up to 4.4
All versions
All versions
Up to 2.74c
Up to 2.004e
All versions
Up to 1.167z
Up to 5.001b
All versions
All versions
All versions
All versions
Up to 1.53f
Up to 3.73b
Up to 1.82l
All versions
Up to 1.04e

References (6)

Source: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Source: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Source: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.