目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2021-20587— Mitsubishi Electric FA engineering software 缓冲区错误漏洞

一分钟漏洞结论

影响对象
Mitsubishi Electric Corporation CPU Module Logging Configuration Tool
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Mitsubishi Electric FA engineering software是日本三菱电机(Mitsubishi Electric)公司的一个工程软件。提供提高设计和调试的效率,减少停机时间和保护数据。 Mitsubishi Electric FA engineering software 存在缓冲区错误漏洞。多款 Mitsubishi Electric FA engineering 软件中存在输入验证错误漏洞。攻击者可能通过欺骗 MELSEC, GOT, or FREQROL 并返回特制的恢复

CVSS 7.5 · High EPSS 3.89% · P89
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2021-20587 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
N/A
来源: CVE Program / CVE List V5
Vulnerability Description
Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3 all versions, FR Configurator2 versions 1.24A and prior, GT Designer3 Version1(GOT1000) versions 1.250L and prior, GT Designer3 Version1(GOT2000) versions 1.250L and prior, GT SoftGOT1000 Version3 versions 3.245F and prior, GT SoftGOT2000 Version1 versions 1.250L and prior, GX Configurator-DP versions 7.14Q and prior, GX Configurator-QP all versions, GX Developer versions 8.506C and prior, GX Explorer all versions, GX IEC Developer all versions, GX LogViewer versions 1.115U and prior, GX RemoteService-I all versions, GX Works2 versions 1.597X and prior, GX Works3 versions 1.070Y and prior, iQ Monozukuri ANDON (Data Transfer) versions 1.003D and prior, iQ Monozukuri Process Remote Monitoring (Data Transfer) versions 1.002C and prior, M_CommDTM-HART all versions, M_CommDTM-IO-Link versions 1.03D and prior, MELFA-Works versions 4.4 and prior, MELSEC WinCPU Setting Utility all versions, MELSOFT EM Software Development Kit (EM Configurator) versions 1.015R and prior, MELSOFT Navigator versions 2.74C and prior, MH11 SettingTool Version2 versions 2.004E and prior, MI Configurator versions 1.004E and prior, MT Works2 versions 1.167Z and prior, MX Component versions 5.001B and prior, Network Interface Board CC IE Control utility versions 1.29F and prior, Network Interface Board CC IE Field Utility versions 1.16S and prior, Network Interface Board CC-Link Ver.2 Utility versions 1.23Z and prior, Network Interface Board MNETH utility versions 34L and prior, PX Developer versions 1.53F and prior, RT ToolBox2 versions 3.73B and prior, RT ToolBox3 versions 1.82L and prior, Setting/monitoring tools for the C Controller module (SW4PVC-CCPU) versions 4.12N and prior, and SLMP Data Collector versions 1.04E and prior) allows a remote unauthenticated attacker to cause a DoS condition on the software products, and possibly to execute a malicious code on the personal computer running the software products although it has not been reproduced, by spoofing MELSEC, GOT or FREQROL and returning crafted reply packets.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
堆缓冲区溢出
来源: CVE Program / CVE List V5
Vulnerability Title
Mitsubishi Electric FA engineering software 缓冲区错误漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Mitsubishi Electric FA engineering software是日本三菱电机(Mitsubishi Electric)公司的一个工程软件。提供提高设计和调试的效率,减少停机时间和保护数据。 Mitsubishi Electric FA engineering software 存在缓冲区错误漏洞。多款 Mitsubishi Electric FA engineering 软件中存在输入验证错误漏洞。攻击者可能通过欺骗 MELSEC, GOT, or FREQROL 并返回特制的恢复
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
Mitsubishi Electric Corporation CPU Module Logging Configuration Tool 1.112R and prior -
Mitsubishi Electric Corporation CW Configurator 1.011M and prior -
Mitsubishi Electric Corporation Data Transfer 3.44W and prior -
Mitsubishi Electric Corporation EZSocket 5.4 and prior -
Mitsubishi Electric Corporation FR Configurator all versions -
Mitsubishi Electric Corporation FR Configurator SW3 all versions -
Mitsubishi Electric Corporation FR Configurator2 1.24A and prior -
Mitsubishi Electric Corporation GT Designer3 Version1(GOT1000) 1.250L and prior -
Mitsubishi Electric Corporation GT Designer3 Version1(GOT2000) 1.250L and prior -
Mitsubishi Electric Corporation GT SoftGOT1000 Version3 3.245F and prior -
Mitsubishi Electric Corporation GT SoftGOT2000 Version1 1.250L and prior -
Mitsubishi Electric Corporation GX Configurator-DP 7.14Q and prior -
Mitsubishi Electric Corporation GX Configurator-QP all versions -
Mitsubishi Electric Corporation GX Developer 8.506C and prior -
Mitsubishi Electric Corporation GX Explorer all versions -
Mitsubishi Electric Corporation GX IEC Developer all versions -
Mitsubishi Electric Corporation GX LogViewer 1.115U and prior -
Mitsubishi Electric Corporation GX RemoteService-I all versions -
Mitsubishi Electric Corporation GX Works2 1.597X and prior -
Mitsubishi Electric Corporation GX Works3 1.070Y and prior -
Mitsubishi Electric Corporation iQ Monozukuri ANDON (Data Transfer) 1.003D and prior -
Mitsubishi Electric Corporation iQ Monozukuri Process Remote Monitoring (Data Transfer) 1.002C and prior -
Mitsubishi Electric Corporation M_CommDTM-HART all versions -
Mitsubishi Electric Corporation M_CommDTM-IO-Link 1.03D and prior -
Mitsubishi Electric Corporation MELFA-Works 4.4 and prior -
Mitsubishi Electric Corporation MELSEC WinCPU Setting Utility all versions -
Mitsubishi Electric Corporation MELSOFT EM Software Development Kit (EM Configurator) 1.015R and prior -
Mitsubishi Electric Corporation MELSOFT Navigator 2.74C and prior -
Mitsubishi Electric Corporation MH11 SettingTool Version2 2.004E and prior -
Mitsubishi Electric Corporation MI Configurator 1.004E and prior -

二、漏洞 CVE-2021-20587 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2021-20587 的情报信息

登录查看更多情报信息。

CVE-2021-20587 厂商安全公告 (5)

CVE-2021-20587 其他参考 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2021-20587

暂无评论


发表评论