Mitsubishi · Mitsubishi Electric Fa Engineering · CVE-2021-20587
Name of the Vulnerable Software and Affected Versions:
Mitsubishi Electric FA Engineering Software versions prior to the fixed version
Description:
A heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software allows a remote unauthenticated attacker to cause a DoS condition of the software products, and possibly to execute a malicious program on the personal computer running the software products, by spoofing MELSEC, GOT or FREQROL and returning crafted reply packets.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.