CVE-2021-20607
Last modified
CVE-2021-20607 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Integer Underflow vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior, Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior and Mitsubishi Electric EZSocket versions 5.4 and prior allows an attacker to cause a DoS condition in the software by getting a user to open malicious project file specially crafted by an attacker.. EPSS estimates a 0.93% chance of exploitation in the next 30 days.
Description
Integer Underflow vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior, Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior and Mitsubishi Electric EZSocket versions 5.4 and prior allows an attacker to cause a DoS condition in the software by getting a user to open malicious project file specially crafted by an attacker.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mitsubishielectric | Ezsocket | <= 5.4 |
| Mitsubishielectric | Gx Works2 | <= 1.606g |
| Mitsubishielectric | Melsoft Navigator | All versions |
References
- https://jvn.jp/vu/JVNVU93817405/index.htmlPatch, Third Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-350-05Third Party Advisory, US Government Resource
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-021_en.pdfPatch, Vendor Advisory
- https://jvn.jp/vu/JVNVU93817405/index.htmlPatch, Third Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-350-05Third Party Advisory, US Government Resource
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-021_en.pdfPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-20607?
How severe is CVE-2021-20607?
How do I fix CVE-2021-20607?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-20601Improper input validation vulnerability in GOT2000 series GT…7.5
- CVE-2021-20602Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-20603Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-20604Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-20605Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-20606Out-of-bounds Read vulnerability in Mitsubishi Electric GX W…5.5
- CVE-2021-20608Improper Handling of Length Parameter Inconsistency vulnerab…7.5
- CVE-2021-20609Uncontrolled Resource Consumption vulnerability in Mitsubish…7.5
- CVE-2021-2061Vulnerability in the MySQL Server product of Oracle MySQL (c…4.4
- CVE-2021-20610Improper Handling of Length Parameter Inconsistency vulnerab…7.5
- CVE-2021-20611Improper Input Validation vulnerability in Mitsubishi Electr…7.5
- CVE-2021-20612Lack of administrator control over security vulnerability in…7.5
Are you affected by CVE-2021-20607?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
