PT-2021-14061 · Mitsubishi · Iq Monozukuri Andon+39
Dliangfun
·
Published
2021-02-19
·
Updated
2025-06-13
·
CVE-2021-20588
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Mitsubishi Electric FA Engineering Software versions prior to the fixed version
CPU Module Logging Configuration Tool versions 1.112R and prior
CW Configurator versions 1.011M and prior
Data Transfer versions 3.44W and prior
EZSocket versions 5.4 and prior
FR Configurator all versions
FR Configurator SW3 all versions
FR Configurator2 versions 1.24A and prior
GT Designer3 Version1(GOT1000) versions 1.250L and prior
GT Designer3 Version1(GOT2000) versions 1.250L and prior
GT SoftGOT1000 Version3 versions 3.245F and prior
GT SoftGOT2000 Version1 versions 1.250L and prior
GX Configurator-DP versions 7.14Q and prior
GX Configurator-QP all versions
GX Developer versions 8.506C and prior
GX Explorer all versions
GX IEC Developer all versions
GX LogViewer versions 1.115U and prior
GX RemoteService-I all versions
GX Works2 versions 1.597X and prior
GX Works3 versions 1.070Y and prior
iQ Monozukuri ANDON (Data Transfer) all versions
iQ Monozukuri Process Remote Monitoring (Data Transfer) all versions
M CommDTM-HART all versions
M CommDTM-IO-Link versions 1.03D and prior
MELFA-Works versions 4.4 and prior
MELSEC WinCPU Setting Utility all versions
MELSOFT EM Software Development Kit (EM Configurator) versions 1.015R and prior
MELSOFT Navigator versions 2.74C and prior
MH11 SettingTool Version2 versions 2.004E and prior
MI Configurator versions 1.004E and prior
MT Works2 versions 1.167Z and prior
MX Component versions 5.001B and prior
Network Interface Board CC IE Control utility versions 1.29F and prior
Network Interface Board CC IE Field Utility versions 1.16S and prior
Network Interface Board CC-Link Ver.2 Utility versions 1.23Z and prior
Network Interface Board MNETH utility versions 34L and prior
PX Developer versions 1.53F and prior
RT ToolBox2 versions 3.73B and prior
RT ToolBox3 versions 1.82L and prior
Setting/monitoring tools for the C Controller module (SW4PVC-CCPU) versions 4.12N and prior
SLMP Data Collector versions 1.04E and prior
Description:
The issue is related to improper handling of length parameter inconsistency, allowing a remote unauthenticated attacker to cause a DoS condition of the software products and possibly execute a malicious program on the personal computer running the software products by spoofing MELSEC, GOT, or FREQROL and returning crafted reply packets.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cpu Module Logging Configuration Tool
Cw Configurator
Data Transfer
Ezsocket
Fr Configurator
Fr Configurator Sw3
Fr Configurator2
Gt Designer3 Version1
Gt Softgot1000 Version3
Gt Softgot2000 Version1
Gx Configurator-Dp
Gx Configurator-Qp
Gx Developer
Gx Explorer
Gx Iec Developer
Gx Logviewer
Gx Remoteservice-I
Gx Works2
Gx Works3
Melfa-Works
Melsec Wincpu Setting Utility
Melsoft Em Software Development Kit
Melsoft Navigator
Mh11 Settingtool Version2
Mi Configurator
Mt Works2
Mx
M Commdtm-Hart
M Commdtm-Io-Link
Mitsubishi Electric Fa Engineering
Network Interface Board Cc Ie Control Utility
Network Interface Board Cc Ie Field Utility
Network Interface Board Cc-Link Ver.2 Utility
Network Interface Board Mneth Utility
Rt Toolbox2
Rt Toolbox3
Slmp Data Collector
Setting/Monitoring Tools For The C Controller Module
Iq Monozukuri Andon
Iq Monozukuri Process Remote Monitoring