CVE Database
/

CVE-2020-14523

Back to search

CVE-2020-14523

Published: Feb 11, 2022

Modified: Apr 16, 2025

PUBLISHED

CVSS v3.1

8.3

HIGH

Description

Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.

VendorProductVersions

Mitsubishi Electric

CW Configurator

affected
unspecified - <= Version 1.010L

Mitsubishi Electric

FR Configurator2

affected
unspecified - <= Version 1.22Y

Mitsubishi Electric

GX Works2

affected
unspecified - <= Version 1.595V

Mitsubishi Electric

GX Works3

affected
unspecified - <= Version 1.063R

Mitsubishi Electric

MELSOFT iQ AppPortal

affected
unspecified - <= Version 1.17T

Mitsubishi Electric

MELSOFT Navigator

affected
unspecified - <= Version2.70Y

Mitsubishi Electric

MI Configurator

affected
All Versions

Mitsubishi Electric

MR Configurator2

affected
unspecified - <= Version 1.110Q

Mitsubishi Electric

MT Works2

affected
unspecified - <= Versions 1.156N

Mitsubishi Electric

MX Component

affected
unspecified - <= Version 4.20W

Mitsubishi Electric

RT ToolBox3

affected
unspecified - <= Versions 1.70Y

Mitsubishi Electric

MELSEC iQ-R Series Motion Module

affected
unspecified - <= Versions 10

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

Required

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now