CVE-2020-14521 (GCVE-0-2020-14521)
Vulnerability from cvelistv5
Published
2022-02-11 17:40
Modified
2025-04-16 18:01
CWE
  • CWE-428 - Unquoted Search Path or Element
Summary
Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.
Impacted products
Vendor Product Version
Mitsubishi Electric C Controller Interface Module Utility Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric CC-Link IE Control Network Data Collector Version: Version 1.00A
Create a notification for this product.
   Mitsubishi Electric CC-Link IE Field Network Data Collector Version: Version 1.00A
Create a notification for this product.
   Mitsubishi Electric CC-Link IE TSN Data Collector Version: Version 1.00A
Create a notification for this product.
   Mitsubishi Electric CPU Module Logging Configuration Tool Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric CW Configurator Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric Data Transfer Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric EZSocket Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric FR Configurator SW3 Version: All Versions
Create a notification for this product.
   Mitsubishi Electric FR Configurator2 Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric GT Designer2 Classic Version: All Versions
Create a notification for this product.
   Mitsubishi Electric GT Designer3 Version1 (GOT1000) Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric GT Designer3 Version1 (GOT2000) Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric GT SoftGOT1000 Version3 Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric GT SoftGOT2000 Version1 Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric GX Developer Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric GX LogViewer Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric GX Works2 Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric GX Works3 Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric M_CommDTM-IO-Link Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric MELFA-Works Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric MELSEC WinCPU Setting Utility Version: All Versions
Create a notification for this product.
   Mitsubishi Electric MELSOFT Complete Clean Up Tool Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric MELSOFT EM Software Development Kit Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric MELSOFT iQ AppPortal Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric MELSOFT Navigator Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric MI Configurator Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric Motion Control Setting Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric Motorizer Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric MR Configurator2 Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric MT Works2 Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric MTConnect Data Collector Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric MX Component Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric MX MESInterface Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric MX MESInterface-R Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric MX Sheet Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric Network Interface Board CC IE Control Utility Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric Network Interface Board CC IE Field Utility Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric Network Interface Board CC-Link Ver.2 Utility Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric Network Interface Board MNETH Utility Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric Position Board utility 2 Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric PX Developer Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric RT ToolBox2 Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric RT ToolBox3 Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric Setting/Monitoring tools for the C Controller module Version: unspecified   <
Version: unspecified   <
Create a notification for this product.
   Mitsubishi Electric SLMP Data Collector Version: unspecified   <
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-04T12:46:34.835Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "government-resource",
              "x_transferred"
            ],
            "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-04"
          },
          {
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-007_en.pdf"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2020-14521",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-04-16T17:31:29.570752Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-04-16T18:01:31.445Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "C Controller Interface Module Utility",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 2.00",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "CC-Link IE Control Network Data Collector",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "status": "affected",
              "version": "Version 1.00A"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "CC-Link IE Field Network Data Collector",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "status": "affected",
              "version": "Version 1.00A"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "CC-Link IE TSN Data Collector",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "status": "affected",
              "version": "Version 1.00A"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "CPU Module Logging Configuration Tool",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.100E",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "CW Configurator",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.010L",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Data Transfer",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 3.42U",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "EZSocket",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 5.1",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "FR Configurator SW3",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "status": "affected",
              "version": "All Versions"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "FR Configurator2",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.26C",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "GT Designer2 Classic",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "status": "affected",
              "version": "All Versions"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "GT Designer3 Version1 (GOT1000)",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.241B",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "GT Designer3 Version1 (GOT2000)",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.241B",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "GT SoftGOT1000 Version3",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 3.200J",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "GT SoftGOT2000 Version1",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.241B",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "GX Developer",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 8.504A",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "GX LogViewer",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.100E",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "GX Works2",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.601B",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "GX Works3",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.063R",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "M_CommDTM-IO-Link",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.03D",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "MELFA-Works",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 4.4",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "MELSEC WinCPU Setting Utility",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "status": "affected",
              "version": "All Versions"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "MELSOFT Complete Clean Up Tool",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.06G",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "MELSOFT EM Software Development Kit",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.015R",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "MELSOFT iQ AppPortal",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.17T",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "MELSOFT Navigator",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 2.74C",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "MI Configurator",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.004E",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Motion Control Setting",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.005F",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Motorizer",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.005F",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "MR Configurator2",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.125F",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "MT Works2",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.167Z",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "MTConnect Data Collector",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.1.4.0",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "MX Component",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 4.20W",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "MX MESInterface",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.21X",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "MX MESInterface-R",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.12N",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "MX Sheet",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 2.15R",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Network Interface Board CC IE Control Utility",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.29F",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Network Interface Board CC IE Field Utility",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Versions 1.16S",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Network Interface Board CC-Link Ver.2 Utility",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.23Z",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Network Interface Board MNETH Utility",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 34L",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Position Board utility 2",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 3.20",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "PX Developer",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.53F",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "RT ToolBox2",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 3.73B",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "RT ToolBox3",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.82L",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Setting/Monitoring tools for the C Controller module",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "SW3PVC-CCPU Version 3.13P",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            },
            {
              "lessThanOrEqual": "SW4PVC-CCPU Version 4.12N",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "SLMP Data Collector",
          "vendor": "Mitsubishi Electric",
          "versions": [
            {
              "lessThanOrEqual": "Version 1.04E",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "user": "00000000-0000-4000-9000-000000000000",
          "value": "Mashav Sapir of Claroty reported this vulnerability to CISA"
        }
      ],
      "datePublic": "2020-07-30T06:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.\n\n\u003cp\u003e\u003c/p\u003e"
            }
          ],
          "value": "Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.3,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-428",
              "description": "CWE-428 Unquoted Search Path or Element",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2023-03-07T21:29:25.280Z",
        "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "shortName": "icscert"
      },
      "references": [
        {
          "tags": [
            "government-resource"
          ],
          "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-04"
        },
        {
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-007_en.pdf"
        }
      ],
      "source": {
        "advisory": "ICSA-20-212-04",
        "discovery": "UNKNOWN"
      },
      "title": "Mitsubishi Electric Factory Automation Engineering Products Unquoted Search Path or Element",
      "x_generator": {
        "engine": "Vulnogram 0.0.9"
      },
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "ics-cert@hq.dhs.gov",
          "DATE_PUBLIC": "2020-07-30T16:50:00.000Z",
          "ID": "CVE-2020-14521",
          "STATE": "PUBLIC",
          "TITLE": "Mitsubishi Electric Factory Automation Engineering Products Unquoted Search Path or Element"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "C Controller Interface Module Utility",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "All Versions"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "C Controller Module Setting and Monitoring Tool",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "All Versions"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "CC-Link IE Control Network Data Collector",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "Version 1.00A"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "CC-Link IE Field Network Data Collector",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "Version 1.00A"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "CC-Link IE TSN Data Collector",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "Version 1.00A"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "CPU Module Logging Configuration Tool",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 1.100E"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "CW Configurator",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 1.010L"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Data Transfer",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 3.42U and prior"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "EZSocket",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 5.1"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "FR Configurator SW3",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "All Versions"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "FR Configurator2",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "All Versions"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "GT Designer2 Classic",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "All Versions"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "GT Designer3 Version1 (GOT1000)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 1.241B"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "GT Designer3 Version1 (GOT2000)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 1.241B"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "GT SoftGOT1000 Version3",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 3.200J"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "GT SoftGOT2000 Version1",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 1.241B"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "GX Developer",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 8.504A"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "GX LogViewer",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 1.100E"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "GX Works2",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 1.601B"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "GX Works3",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 1.063R"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "M_CommDTM-IO-Link",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "All Versions"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "MELFA-Works",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 4.4"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "MELSEC WinCPU Setting Utility",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "All Versions"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "MELSOFT Complete Clean Up Tool",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 1.06G"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "MELSOFT EM Software Development Kit",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "All Versions"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "MELSOFT iQ AppPortal",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 1.17T"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "MELSOFT Navigator",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 2.74C"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "MI Configurator",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "All Versions"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Motion Control Setting",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 1.005F"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Motorizer",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 1.005F"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "MR Configurator2",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 1.125F"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "MT Works2",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 1.167Z"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "MTConnect Data Collector",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 1.1.4.0"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "MX Component",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 4.20W"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "MX MESInterface",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 1.21X"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "MX MESInterface-R",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 1.12N"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "MX Sheet",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 2.15R"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Network Interface Board CC IE Control Utility",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "All Versions"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Network Interface Board CC IE Field Utility",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "All Versions"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Network Interface Board CC-Link Ver.2 Utility",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "All Versions"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Network Interface Board MNETH Utility",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "All Versions"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Position Board utility 2",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "All Versions"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "PX Developer",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "version 1.53F"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "RT ToolBox2",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 3.73B"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "RT ToolBox3",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 1.82L"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Setting/monitoring tools for the C Controller module",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "All Versions"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "SLMP Data Collector",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c=",
                            "version_value": "Version 1.04E"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "Mitsubishi Electric"
              }
            ]
          }
        },
        "credit": [
          {
            "lang": "eng",
            "value": "Mashav Sapir of Claroty reported this vulnerability to CISA"
          }
        ],
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition."
            }
          ]
        },
        "generator": {
          "engine": "Vulnogram 0.0.9"
        },
        "impact": {
          "cvss": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.3,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H",
            "version": "3.1"
          }
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "CWE-428 Unquoted Search Path or Element"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-04",
              "refsource": "MISC",
              "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-04"
            },
            {
              "name": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-007_en.pdf",
              "refsource": "MISC",
              "url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-007_en.pdf"
            }
          ]
        },
        "solution": [
          {
            "lang": "en"
          }
        ],
        "source": {
          "advisory": "ICSA-20-212-04",
          "discovery": "UNKNOWN"
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
    "assignerShortName": "icscert",
    "cveId": "CVE-2020-14521",
    "datePublished": "2022-02-11T17:40:28.403Z",
    "dateReserved": "2020-06-19T00:00:00.000Z",
    "dateUpdated": "2025-04-16T18:01:31.445Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-04\", \"tags\": [\"government-resource\", \"x_transferred\"]}, {\"url\": \"https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-007_en.pdf\", \"tags\": [\"vendor-advisory\", \"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-04T12:46:34.835Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2020-14521\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"total\"}], \"version\": \"2.0.3\", \"timestamp\": \"2025-04-16T17:31:29.570752Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2025-04-16T17:31:31.459Z\"}}], \"cna\": {\"title\": \"Mitsubishi Electric Factory Automation Engineering Products Unquoted Search Path or Element\", \"source\": {\"advisory\": \"ICSA-20-212-04\", \"discovery\": \"UNKNOWN\"}, \"credits\": [{\"lang\": \"en\", \"type\": \"finder\", \"user\": \"00000000-0000-4000-9000-000000000000\", \"value\": \"Mashav Sapir of Claroty reported this vulnerability to CISA\"}], \"metrics\": [{\"format\": \"CVSS\", \"cvssV3_1\": {\"scope\": \"CHANGED\", \"version\": \"3.1\", \"baseScore\": 8.3, \"attackVector\": \"NETWORK\", \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H\", \"integrityImpact\": \"HIGH\", \"userInteraction\": \"REQUIRED\", \"attackComplexity\": \"HIGH\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"NONE\", \"confidentialityImpact\": \"HIGH\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"GENERAL\"}]}], \"affected\": [{\"vendor\": \"Mitsubishi Electric\", \"product\": \"C Controller Interface Module Utility\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 2.00\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"CC-Link IE Control Network Data Collector\", \"versions\": [{\"status\": \"affected\", \"version\": \"Version 1.00A\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"CC-Link IE Field Network Data Collector\", \"versions\": [{\"status\": \"affected\", \"version\": \"Version 1.00A\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"CC-Link IE TSN Data Collector\", \"versions\": [{\"status\": \"affected\", \"version\": \"Version 1.00A\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"CPU Module Logging Configuration Tool\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.100E\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"CW Configurator\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.010L\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"Data Transfer\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 3.42U\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"EZSocket\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 5.1\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"FR Configurator SW3\", \"versions\": [{\"status\": \"affected\", \"version\": \"All Versions\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"FR Configurator2\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.26C\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"GT Designer2 Classic\", \"versions\": [{\"status\": \"affected\", \"version\": \"All Versions\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"GT Designer3 Version1 (GOT1000)\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.241B\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"GT Designer3 Version1 (GOT2000)\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.241B\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"GT SoftGOT1000 Version3\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 3.200J\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"GT SoftGOT2000 Version1\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.241B\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"GX Developer\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 8.504A\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"GX LogViewer\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.100E\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"GX Works2\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.601B\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"GX Works3\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.063R\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"M_CommDTM-IO-Link\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.03D\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"MELFA-Works\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 4.4\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"MELSEC WinCPU Setting Utility\", \"versions\": [{\"status\": \"affected\", \"version\": \"All Versions\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"MELSOFT Complete Clean Up Tool\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.06G\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"MELSOFT EM Software Development Kit\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.015R\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"MELSOFT iQ AppPortal\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.17T\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"MELSOFT Navigator\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 2.74C\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"MI Configurator\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.004E\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"Motion Control Setting\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.005F\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"Motorizer\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.005F\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"MR Configurator2\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.125F\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"MT Works2\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.167Z\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"MTConnect Data Collector\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.1.4.0\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"MX Component\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 4.20W\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"MX MESInterface\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.21X\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"MX MESInterface-R\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.12N\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"MX Sheet\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 2.15R\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"Network Interface Board CC IE Control Utility\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.29F\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"Network Interface Board CC IE Field Utility\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Versions 1.16S\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"Network Interface Board CC-Link Ver.2 Utility\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.23Z\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"Network Interface Board MNETH Utility\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 34L\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"Position Board utility 2\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 3.20\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"PX Developer\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.53F\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"RT ToolBox2\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 3.73B\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"RT ToolBox3\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.82L\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"Setting/Monitoring tools for the C Controller module\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"SW3PVC-CCPU Version 3.13P\"}, {\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"SW4PVC-CCPU Version 4.12N\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Mitsubishi Electric\", \"product\": \"SLMP Data Collector\", \"versions\": [{\"status\": \"affected\", \"version\": \"unspecified\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"Version 1.04E\"}], \"defaultStatus\": \"unaffected\"}], \"datePublic\": \"2020-07-30T06:00:00.000Z\", \"references\": [{\"url\": \"https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-04\", \"tags\": [\"government-resource\"]}, {\"url\": \"https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-007_en.pdf\", \"tags\": [\"vendor-advisory\"]}], \"x_generator\": {\"engine\": \"Vulnogram 0.0.9\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.\\n\\n\u003cp\u003e\u003c/p\u003e\", \"base64\": false}]}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-428\", \"description\": \"CWE-428 Unquoted Search Path or Element\"}]}], \"providerMetadata\": {\"orgId\": \"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6\", \"shortName\": \"icscert\", \"dateUpdated\": \"2023-03-07T21:29:25.280Z\"}, \"x_legacyV4Record\": {\"credit\": [{\"lang\": \"eng\", \"value\": \"Mashav Sapir of Claroty reported this vulnerability to CISA\"}], \"impact\": {\"cvss\": {\"scope\": \"CHANGED\", \"version\": \"3.1\", \"baseScore\": 8.3, \"attackVector\": \"NETWORK\", \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H\", \"integrityImpact\": \"HIGH\", \"userInteraction\": \"REQUIRED\", \"attackComplexity\": \"HIGH\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"NONE\", \"confidentialityImpact\": \"HIGH\"}}, \"source\": {\"advisory\": \"ICSA-20-212-04\", \"discovery\": \"UNKNOWN\"}, \"affects\": {\"vendor\": {\"vendor_data\": [{\"product\": {\"product_data\": [{\"version\": {\"version_data\": [{\"version_value\": \"All Versions\", \"version_affected\": \"=\"}]}, \"product_name\": \"C Controller Interface Module Utility\"}, {\"version\": {\"version_data\": [{\"version_value\": \"All Versions\", \"version_affected\": \"=\"}]}, \"product_name\": \"C Controller Module Setting and Monitoring Tool\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.00A\", \"version_affected\": \"=\"}]}, \"product_name\": \"CC-Link IE Control Network Data Collector\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.00A\", \"version_affected\": \"=\"}]}, \"product_name\": \"CC-Link IE Field Network Data Collector\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.00A\", \"version_affected\": \"=\"}]}, \"product_name\": \"CC-Link IE TSN Data Collector\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.100E\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"CPU Module Logging Configuration Tool\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.010L\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"CW Configurator\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 3.42U and prior\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"Data Transfer\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 5.1\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"EZSocket\"}, {\"version\": {\"version_data\": [{\"version_value\": \"All Versions\", \"version_affected\": \"=\"}]}, \"product_name\": \"FR Configurator SW3\"}, {\"version\": {\"version_data\": [{\"version_value\": \"All Versions\", \"version_affected\": \"=\"}]}, \"product_name\": \"FR Configurator2\"}, {\"version\": {\"version_data\": [{\"version_value\": \"All Versions\", \"version_affected\": \"=\"}]}, \"product_name\": \"GT Designer2 Classic\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.241B\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"GT Designer3 Version1 (GOT1000)\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.241B\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"GT Designer3 Version1 (GOT2000)\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 3.200J\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"GT SoftGOT1000 Version3\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.241B\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"GT SoftGOT2000 Version1\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 8.504A\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"GX Developer\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.100E\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"GX LogViewer\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.601B\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"GX Works2\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.063R\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"GX Works3\"}, {\"version\": {\"version_data\": [{\"version_value\": \"All Versions\", \"version_affected\": \"=\"}]}, \"product_name\": \"M_CommDTM-IO-Link\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 4.4\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"MELFA-Works\"}, {\"version\": {\"version_data\": [{\"version_value\": \"All Versions\", \"version_affected\": \"=\"}]}, \"product_name\": \"MELSEC WinCPU Setting Utility\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.06G\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"MELSOFT Complete Clean Up Tool\"}, {\"version\": {\"version_data\": [{\"version_value\": \"All Versions\", \"version_affected\": \"=\"}]}, \"product_name\": \"MELSOFT EM Software Development Kit\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.17T\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"MELSOFT iQ AppPortal\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 2.74C\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"MELSOFT Navigator\"}, {\"version\": {\"version_data\": [{\"version_value\": \"All Versions\", \"version_affected\": \"=\"}]}, \"product_name\": \"MI Configurator\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.005F\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"Motion Control Setting\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.005F\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"Motorizer\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.125F\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"MR Configurator2\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.167Z\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"MT Works2\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.1.4.0\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"MTConnect Data Collector\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 4.20W\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"MX Component\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.21X\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"MX MESInterface\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.12N\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"MX MESInterface-R\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 2.15R\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"MX Sheet\"}, {\"version\": {\"version_data\": [{\"version_value\": \"All Versions\", \"version_affected\": \"=\"}]}, \"product_name\": \"Network Interface Board CC IE Control Utility\"}, {\"version\": {\"version_data\": [{\"version_value\": \"All Versions\", \"version_affected\": \"=\"}]}, \"product_name\": \"Network Interface Board CC IE Field Utility\"}, {\"version\": {\"version_data\": [{\"version_value\": \"All Versions\", \"version_affected\": \"=\"}]}, \"product_name\": \"Network Interface Board CC-Link Ver.2 Utility\"}, {\"version\": {\"version_data\": [{\"version_value\": \"All Versions\", \"version_affected\": \"=\"}]}, \"product_name\": \"Network Interface Board MNETH Utility\"}, {\"version\": {\"version_data\": [{\"version_value\": \"All Versions\", \"version_affected\": \"=\"}]}, \"product_name\": \"Position Board utility 2\"}, {\"version\": {\"version_data\": [{\"version_value\": \"version 1.53F\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"PX Developer\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 3.73B\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"RT ToolBox2\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.82L\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"RT ToolBox3\"}, {\"version\": {\"version_data\": [{\"version_value\": \"All Versions\", \"version_affected\": \"=\"}]}, \"product_name\": \"Setting/monitoring tools for the C Controller module\"}, {\"version\": {\"version_data\": [{\"version_value\": \"Version 1.04E\", \"version_affected\": \"\u003c=\"}]}, \"product_name\": \"SLMP Data Collector\"}]}, \"vendor_name\": \"Mitsubishi Electric\"}]}}, \"solution\": [{\"lang\": \"en\"}], \"data_type\": \"CVE\", \"generator\": {\"engine\": \"Vulnogram 0.0.9\"}, \"references\": {\"reference_data\": [{\"url\": \"https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-04\", \"name\": \"https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-04\", \"refsource\": \"MISC\"}, {\"url\": \"https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-007_en.pdf\", \"name\": \"https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-007_en.pdf\", \"refsource\": \"MISC\"}]}, \"data_format\": \"MITRE\", \"description\": {\"description_data\": [{\"lang\": \"eng\", \"value\": \"Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.\"}]}, \"problemtype\": {\"problemtype_data\": [{\"description\": [{\"lang\": \"eng\", \"value\": \"CWE-428 Unquoted Search Path or Element\"}]}]}, \"data_version\": \"4.0\", \"CVE_data_meta\": {\"ID\": \"CVE-2020-14521\", \"STATE\": \"PUBLIC\", \"TITLE\": \"Mitsubishi Electric Factory Automation Engineering Products Unquoted Search Path or Element\", \"ASSIGNER\": \"ics-cert@hq.dhs.gov\", \"DATE_PUBLIC\": \"2020-07-30T16:50:00.000Z\"}}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2020-14521\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2025-04-16T18:01:31.445Z\", \"dateReserved\": \"2020-06-19T00:00:00.000Z\", \"assignerOrgId\": \"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6\", \"datePublished\": \"2022-02-11T17:40:28.403Z\", \"assignerShortName\": \"icscert\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…