Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2021-20588

Quick assessment

Affected
Mitsubishi Electric Corporation CPU Module Logging Configuration Tool
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Mitsubishi Electric FA engineering software是日本三菱电机(Mitsubishi Electric)公司的一个工程软件。提供提高设计和调试的效率,减少停机时间和保护数据。 Mitsubishi Electric FA engineering software 中存在缓冲区错误漏洞。该漏洞源于软件对参数长度的处理不当,攻击者可能通过欺骗 MELSEC、GOT 或 FREQROL 并返回特制的恢复数据包从而引起导致拒绝服务。

CVSS 7.5 · High EPSS 6.88% · P94
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-20588

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3 all versions, FR Configurator2 versions 1.24A and prior, GT Designer3 Version1(GOT1000) versions 1.250L and prior, GT Designer3 Version1(GOT2000) versions 1.250L and prior, GT SoftGOT1000 Version3 versions 3.245F and prior, GT SoftGOT2000 Version1 versions 1.250L and prior, GX Configurator-DP versions 7.14Q and prior, GX Configurator-QP all versions, GX Developer versions 8.506C and prior, GX Explorer all versions, GX IEC Developer all versions, GX LogViewer versions 1.115U and prior, GX RemoteService-I all versions, GX Works2 versions 1.597X and prior, GX Works3 versions 1.070Y and prior, iQ Monozukuri ANDON (Data Transfer) versions 1.003D and prior, iQ Monozukuri Process Remote Monitoring (Data Transfer) versions 1.002C and prior, M_CommDTM-HART all versions, M_CommDTM-IO-Link versions 1.03D and prior, MELFA-Works versions 4.4 and prior, MELSEC WinCPU Setting Utility all versions, MELSOFT EM Software Development Kit (EM Configurator) versions 1.015R and prior, MELSOFT Navigator versions 2.74C and prior, MH11 SettingTool Version2 versions 2.004E and prior, MI Configurator versions 1.004E and prior, MT Works2 versions 1.167Z and prior, MX Component versions 5.001B and prior, Network Interface Board CC IE Control utility versions 1.29F and prior, Network Interface Board CC IE Field Utility versions 1.16S and prior, Network Interface Board CC-Link Ver.2 Utility versions 1.23Z and prior, Network Interface Board MNETH utility versions 34L and prior, PX Developer versions 1.53F and prior, RT ToolBox2 versions 3.73B and prior, RT ToolBox3 versions 1.82L and prior, Setting/monitoring tools for the C Controller module (SW4PVC-CCPU) versions 4.12N and prior, and SLMP Data Collector versions 1.04E and prior) allows a remote unauthenticated attacker to cause a DoS condition on the software products, and possibly to execute a malicious code on the personal computer running the software products although it has not been reproduced, by spoofing MELSEC, GOT or FREQROL and returning crafted reply packets.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
长度参数不一致性处理不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
Mitsubishi Electric FA engineering software 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mitsubishi Electric FA engineering software是日本三菱电机(Mitsubishi Electric)公司的一个工程软件。提供提高设计和调试的效率,减少停机时间和保护数据。 Mitsubishi Electric FA engineering software 中存在缓冲区错误漏洞。该漏洞源于软件对参数长度的处理不当,攻击者可能通过欺骗 MELSEC、GOT 或 FREQROL 并返回特制的恢复数据包从而引起导致拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Mitsubishi Electric Corporation CPU Module Logging Configuration Tool 1.112R and prior -
Mitsubishi Electric Corporation CW Configurator 1.011M and prior -
Mitsubishi Electric Corporation Data Transfer 3.44W and prior -
Mitsubishi Electric Corporation EZSocket 5.4 and prior -
Mitsubishi Electric Corporation FR Configurator all versions -
Mitsubishi Electric Corporation FR Configurator SW3 all versions -
Mitsubishi Electric Corporation FR Configurator2 1.24A and prior -
Mitsubishi Electric Corporation GT Designer3 Version1(GOT1000) 1.250L and prior -
Mitsubishi Electric Corporation GT Designer3 Version1(GOT2000) 1.250L and prior -
Mitsubishi Electric Corporation GT SoftGOT1000 Version3 3.245F and prior -
Mitsubishi Electric Corporation GT SoftGOT2000 Version1 1.250L and prior -
Mitsubishi Electric Corporation GX Configurator-DP 7.14Q and prior -
Mitsubishi Electric Corporation GX Configurator-QP all versions -
Mitsubishi Electric Corporation GX Developer 8.506C and prior -
Mitsubishi Electric Corporation GX Explorer all versions -
Mitsubishi Electric Corporation GX IEC Developer all versions -
Mitsubishi Electric Corporation GX LogViewer 1.115U and prior -
Mitsubishi Electric Corporation GX RemoteService-I all versions -
Mitsubishi Electric Corporation GX Works2 1.597X and prior -
Mitsubishi Electric Corporation GX Works3 1.070Y and prior -
Mitsubishi Electric Corporation iQ Monozukuri ANDON (Data Transfer) 1.003D and prior -
Mitsubishi Electric Corporation iQ Monozukuri Process Remote Monitoring (Data Transfer) 1.002C and prior -
Mitsubishi Electric Corporation M_CommDTM-HART all versions -
Mitsubishi Electric Corporation M_CommDTM-IO-Link 1.03D and prior -
Mitsubishi Electric Corporation MELFA-Works 4.4 and prior -
Mitsubishi Electric Corporation MELSEC WinCPU Setting Utility all versions -
Mitsubishi Electric Corporation MELSOFT EM Software Development Kit (EM Configurator) 1.015R and prior -
Mitsubishi Electric Corporation MELSOFT Navigator 2.74C and prior -
Mitsubishi Electric Corporation MH11 SettingTool Version2 2.004E and prior -
Mitsubishi Electric Corporation MI Configurator 1.004E and prior -

II. Public POCs for CVE-2021-20588

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-20588

请登录查看更多情报信息。

Vendor Advisories for CVE-2021-20588 (4)

Other References for CVE-2021-20588 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2021-20588

No comments yet


Leave a comment