CVE-2021-20607
Last modified
CVE-2021-20607 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Integer Underflow vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior, Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior and Mitsubishi Electric EZSocket versions 5.4 and prior allows an attacker to cause a DoS condition in the software by getting a user to open malicious project file specially crafted by an attacker.. EPSS estimates a 0.93% chance of exploitation in the next 30 days.
Description
Integer Underflow vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior, Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior and Mitsubishi Electric EZSocket versions 5.4 and prior allows an attacker to cause a DoS condition in the software by getting a user to open malicious project file specially crafted by an attacker.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mitsubishielectric | Ezsocket | <= 5.4 |
| Mitsubishielectric | Gx Works2 | <= 1.606g |
| Mitsubishielectric | Melsoft Navigator | All versions |
References
- https://jvn.jp/vu/JVNVU93817405/index.htmlPatch, Third Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-350-05Third Party Advisory, US Government Resource
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-021_en.pdfPatch, Vendor Advisory
- https://jvn.jp/vu/JVNVU93817405/index.htmlPatch, Third Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-350-05Third Party Advisory, US Government Resource
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-021_en.pdfPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-20607?
How severe is CVE-2021-20607?
How do I fix CVE-2021-20607?
Are you affected by CVE-2021-20607?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
