PT-2021-14074 · Mitsubishi · Ezsocket+2

Published

2021-12-17

·

Updated

2023-02-02

·

CVE-2021-20606

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Mitsubishi Electric GX Works2 versions 1.606G and prior Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior Mitsubishi Electric EZSocket versions 5.4 and prior
Description: The issue allows an attacker to cause a Denial of Service (DoS) condition in the software by getting a user to open a malicious project file specially crafted by the attacker.
Recommendations: For Mitsubishi Electric GX Works2 versions 1.606G and prior, update to a version later than 1.606G to resolve the issue. For Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior, update to a version later than 2.84N to resolve the issue. For Mitsubishi Electric EZSocket versions 5.4 and prior, update to a version later than 5.4 to resolve the issue.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2021-20606

Affected Products

Ezsocket
Gx Works2
Melsoft Navigator