PT-2021-14076 · Mitsubishi · Gx Works2

Published

2021-12-17

·

Updated

2021-12-27

·

CVE-2021-20608

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Mitsubishi Electric GX Works2 versions 1.606G and prior
Description: The issue allows a remote unauthenticated attacker to cause a Denial of Service (DoS) condition in GX Works2. This is achieved by getting GX Works2 to read a tampered program file from a Mitsubishi Electric PLC, which is done by sending maliciously crafted packets to tamper with the program file.
Recommendations: For versions 1.606G and prior, update to a version later than 1.606G to resolve the issue. As a temporary workaround, consider restricting access to the program files to minimize the risk of exploitation. Avoid using potentially tampered program files from Mitsubishi Electric PLCs until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-20608

Affected Products

Gx Works2