CVE-2020-14523

Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mitsubishielectric:cw_configurator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:fr_configurator2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_works2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_works3:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:iu_configuration_tool:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:iu_developer2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_iq_appportal:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_navigator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mi_configurator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mr_configurator2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mt_works2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mx_component:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:rt_toolbox3:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:mitsubishielectric:rd78g4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:rd78g4:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:mitsubishielectric:rd78g8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:rd78g8:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:mitsubishielectric:rd78g16_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:rd78g16:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:mitsubishielectric:rd78g32_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:rd78g32:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:mitsubishielectric:rd78g64_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:rd78g64:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:mitsubishielectric:rd78ghv_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:rd78ghv:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:mitsubishielectric:rd78ghw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:rd78ghw:-:*:*:*:*:*:*:*

History

01 Mar 2022, 16:20

Type Values Removed Values Added
References (MISC) https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-008_en.pdf - (MISC) https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-008_en.pdf - Vendor Advisory
References (MISC) https://jvn.jp/vu/JVNVU90224831/ - (MISC) https://jvn.jp/vu/JVNVU90224831/ - Third Party Advisory
CPE cpe:2.3:a:mitsubishielectric:iu_developer2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:iu_configuration_tool:*:*:*:*:*:*:*:*

19 Feb 2022, 00:15

Type Values Removed Values Added
References
  • (MISC) https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-008_en.pdf -
  • (MISC) https://jvn.jp/vu/JVNVU90224831/ -

18 Feb 2022, 18:42

Type Values Removed Values Added
CWE CWE-22
References (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-03 - (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-03 - Patch, Third Party Advisory, US Government Resource
CVSS v2 : unknown
v3 : unknown
v2 : 7.5
v3 : 9.8
CPE cpe:2.3:a:mitsubishielectric:mi_configurator:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:rd78ghv_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:rd78g8:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:rd78g8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:rd78g32_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_works2:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:rd78g16:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:rd78g64:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mt_works2:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:rd78ghw:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:rd78ghw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_works3:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mx_component:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mr_configurator2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_navigator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:rt_toolbox3:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:rd78ghv:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:cw_configurator:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:rd78g16_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:rd78g4:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_iq_appportal:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:rd78g4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:fr_configurator2:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:rd78g32:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:rd78g64_firmware:*:*:*:*:*:*:*:*

11 Feb 2022, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-02-11 18:15

Updated : 2024-02-04 22:29


NVD link : CVE-2020-14523

Mitre link : CVE-2020-14523

CVE.ORG link : CVE-2020-14523


JSON object : View

Products Affected

mitsubishielectric

  • gx_works3
  • iu_developer2
  • rd78ghw_firmware
  • rd78g8
  • rd78g8_firmware
  • rd78g16_firmware
  • rd78g32
  • rd78ghw
  • mr_configurator2
  • rd78ghv_firmware
  • rd78g32_firmware
  • rd78g4_firmware
  • melsoft_iq_appportal
  • melsoft_navigator
  • mx_component
  • gx_works2
  • rd78g4
  • rd78g64
  • iu_configuration_tool
  • mi_configurator
  • fr_configurator2
  • rt_toolbox3
  • rd78ghv
  • cw_configurator
  • rd78g16
  • mt_works2
  • rd78g64_firmware
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')