CVE-2020-5602

HIGHCVSS 7.5/10EPSS 1.43%

Last modified

CVE-2020-5602 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. EPSS estimates a 1.43% chance of exploitation in the next 30 days.

Description

Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX LogViewer Ver. 1.96A and earlier, GX Works2 Ver. 1.586L and earlier, GX Works3 Ver. 1.058L and earlier, M_CommDTM-HART Ver. 1.00A, M_CommDTM-IO-Link Ver. 1.02C and earlier, MELFA-Works Ver. 4.3 and earlier, MELSEC-L Flexible High-Speed I/O Control Module Configuration Tool Ver.1.004E and earlier, MELSOFT FieldDeviceConfigurator Ver. 1.03D and earlier, MELSOFT iQ AppPortal Ver. 1.11M and earlier, MELSOFT Navigator Ver. 2.58L and earlier, MI Configurator Ver. 1.003D and earlier, Motion Control Setting Ver. 1.005F and earlier, MR Configurator2 Ver. 1.72A and earlier, MT Works2 Ver. 1.156N and earlier, RT ToolBox2 Ver. 3.72A and earlier, and RT ToolBox3 Ver. 1.50C and earlier) allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vectors.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
1.43%

69.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
MitsubishielectricCpu Module Logging Configuration Tool<= 1.94y
MitsubishielectricCw Configurator<= 1.010l
MitsubishielectricEm Configurator<= 1.010l
MitsubishielectricGt Designer3<= 1.221f
MitsubishielectricGx Logviewer<= 1.100e
MitsubishielectricGx Works2<= 1.590q
MitsubishielectricGx Works3<= 1.060n
MitsubishielectricM Commdtm-Hart<= 1.01b
MitsubishielectricM Commdtm-Io-Link<= 1.03d
MitsubishielectricMelfa-Works<= 4.4
MitsubishielectricMelsec-L Flexible High-Speed I\/O Control Module Configuration Tool<= 1.005f
MitsubishielectricMelsoft Fielddeviceconfigurator<= 1.04e
MitsubishielectricMelsoft Iq Appportal<= 1.14q
MitsubishielectricMelsoft Navigator<= 2.62q
MitsubishielectricMi Configurator<= 1.004e
MitsubishielectricMotion Control Setting<= 1.006g
MitsubishielectricMr Configurator2<= 1.100e
MitsubishielectricMt Works2<= 1.160s
MitsubishielectricRt Toolbox2<= 3.73b
MitsubishielectricRt Toolbox3<= 1.60n

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-5602?
Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX LogViewer Ver. 1.96A and earlier, GX Works2 Ver. 1.586L and earlier, GX Works3 Ver. 1.058L and earlier, M_CommDTM-HART Ver. 1.00A, M_CommDTM-IO-Link Ver. 1.02C and earlier, MELFA-Works Ver. 4.3 and earlier, MELSEC-L Flexible High-Speed I/O Control Module Configuration Tool Ver.1.004E and earlier, MELSOFT FieldDeviceConfigurator Ver. 1.03D and earlier, MELSOFT iQ AppPortal Ver. 1.11M and earlier, MELSOFT Navigator Ver. 2.58L and earlier, MI Configurator Ver. 1.003D and earlier, Motion Control Setting Ver. 1.005F and earlier, MR Configurator2 Ver. 1.72A and earlier, MT Works2 Ver. 1.156N and earlier, RT ToolBox2 Ver. 3.72A and earlier, and RT ToolBox3 Ver. 1.50C and earlier) allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vectors.
How severe is CVE-2020-5602?
CVE-2020-5602 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 1.43% probability of exploitation in the next 30 days.
How do I fix CVE-2020-5602?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-5602?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST