CVE-2020-14521
HIGHMitsubishi Electric Factory Automation - Code Injection
Title source: llmDescription
Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.
References (2)
Core 2
Core References
Third Party Advisory, US Government Resource government-resource
https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-04
Vendor Advisory vendor-advisory
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-007_en.pdf
Scores
CVSS v3
8.3
EPSS
0.0058
EPSS Percentile
69.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-428
CWE-276
Status
published
Products (46)
mitsubishielectric/c_controller_interface_module_utility
mitsubishielectric/c_controller_module_setting_and_monitoring_tool
mitsubishielectric/cc-link_ie_control_network_data_collector
1.00a
mitsubishielectric/cc-link_ie_field_network_data_collector
1.00a
mitsubishielectric/cc-link_ie_tsn_data_collector
1.00a
mitsubishielectric/cpu_module_logging_configuration_tool
< 1.100e
mitsubishielectric/cw_configurator
< 1.010l
mitsubishielectric/data_transfer
< 3.42u
mitsubishielectric/ezsocket
< 5.1
mitsubishielectric/fr_configurator2
... and 36 more
Published
Feb 11, 2022
Tracked Since
Feb 18, 2026