PT-2021-14076 · Mitsubishi · Gx Works2
Published
2021-12-17
·
Updated
2021-12-27
·
CVE-2021-20608
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Mitsubishi Electric GX Works2 versions 1.606G and prior
Description:
The issue allows a remote unauthenticated attacker to cause a Denial of Service (DoS) condition in GX Works2. This is achieved by getting GX Works2 to read a tampered program file from a Mitsubishi Electric PLC, which is done by sending maliciously crafted packets to tamper with the program file.
Recommendations:
For versions 1.606G and prior, update to a version later than 1.606G to resolve the issue. As a temporary workaround, consider restricting access to the program files to minimize the risk of exploitation. Avoid using potentially tampered program files from Mitsubishi Electric PLCs until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gx Works2