CVE-2020-14496

CRITICALCVSS 9.8/10EPSS 0.83%

Last modified

CVE-2020-14496 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed, tampered with, and/or destroyed.. EPSS estimates a 0.83% chance of exploitation in the next 30 days.

Description

Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed, tampered with, and/or destroyed.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.83%

52.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
MitsubishielectricCpu Module Logging Configuration Tool< 1.106k
MitsubishielectricCw Configurator< 1.011m
MitsubishielectricData Transfer< 3.41t
MitsubishielectricEm Configurator< 1.015r
MitsubishielectricEzsocket< 4.6
MitsubishielectricFr Configurator2< 1.23z
MitsubishielectricGt Designer3< 1.236w
MitsubishielectricGt Softgot1000< 3.245f
MitsubishielectricGt Softgot2000< 1.236w
MitsubishielectricGx Logviewer< 1.106k
MitsubishielectricGx Works2< 1.595v
MitsubishielectricGx Works3< 1.065t
MitsubishielectricM Commdtm-Hart< 1.01b
MitsubishielectricM Commdtm-Io-Link< 1.04e
MitsubishielectricMelfa-Works< 4.4
MitsubishielectricMelsoft Fielddeviceconfigurator< 1.04e
MitsubishielectricMelsoft Navigator< 2.70y
MitsubishielectricMh11 Settingtool Version2< 2.003d
MitsubishielectricMotorizer< 1.010l
MitsubishielectricMr Configurator2< 1.106l
MitsubishielectricMt Works2< 1.160s
MitsubishielectricMx Component< 4.20w
MitsubishielectricNetwork Interface Board Cc-Link Ver.2 Utility< 1.24a
MitsubishielectricNetwork Interface Board Cc Ie Control Utility< 1.30g
MitsubishielectricNetwork Interface Board Cc Ie Field Utility< 1.17t
MitsubishielectricNetwork Interface Board Mneth Utility< 35m
MitsubishielectricPx Developer< 1.53f
MitsubishielectricRt Toolbox2< 3.73b
MitsubishielectricRt Toolbox3< 1.80j

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-14496?
Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed, tampered with, and/or destroyed.
How severe is CVE-2020-14496?
CVE-2020-14496 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 0.83% probability of exploitation in the next 30 days.
How do I fix CVE-2020-14496?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-14496?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST