CVE Database
/

CVE-2021-20587

Back to search

CVE-2021-20587

Published: Feb 19, 2021

Modified: Jun 12, 2025

PUBLISHED

CVSS v3.1

7.5

HIGH

Description

Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3 all versions, FR Configurator2 versions 1.24A and prior, GT Designer3 Version1(GOT1000) versions 1.250L and prior, GT Designer3 Version1(GOT2000) versions 1.250L and prior, GT SoftGOT1000 Version3 versions 3.245F and prior, GT SoftGOT2000 Version1 versions 1.250L and prior, GX Configurator-DP versions 7.14Q and prior, GX Configurator-QP all versions, GX Developer versions 8.506C and prior, GX Explorer all versions, GX IEC Developer all versions, GX LogViewer versions 1.115U and prior, GX RemoteService-I all versions, GX Works2 versions 1.597X and prior, GX Works3 versions 1.070Y and prior, iQ Monozukuri ANDON (Data Transfer) versions 1.003D and prior, iQ Monozukuri Process Remote Monitoring (Data Transfer) versions 1.002C and prior, M_CommDTM-HART all versions, M_CommDTM-IO-Link versions 1.03D and prior, MELFA-Works versions 4.4 and prior, MELSEC WinCPU Setting Utility all versions, MELSOFT EM Software Development Kit (EM Configurator) versions 1.015R and prior, MELSOFT Navigator versions 2.74C and prior, MH11 SettingTool Version2 versions 2.004E and prior, MI Configurator versions 1.004E and prior, MT Works2 versions 1.167Z and prior, MX Component versions 5.001B and prior, Network Interface Board CC IE Control utility versions 1.29F and prior, Network Interface Board CC IE Field Utility versions 1.16S and prior, Network Interface Board CC-Link Ver.2 Utility versions 1.23Z and prior, Network Interface Board MNETH utility versions 34L and prior, PX Developer versions 1.53F and prior, RT ToolBox2 versions 3.73B and prior, RT ToolBox3 versions 1.82L and prior, Setting/monitoring tools for the C Controller module (SW4PVC-CCPU) versions 4.12N and prior, and SLMP Data Collector versions 1.04E and prior) allows a remote unauthenticated attacker to cause a DoS condition on the software products, and possibly to execute a malicious code on the personal computer running the software products although it has not been reproduced, by spoofing MELSEC, GOT or FREQROL and returning crafted reply packets.

VendorProductVersions

Mitsubishi Electric Corporation

CPU Module Logging Configuration Tool

affected
1.112R and prior

Mitsubishi Electric Corporation

CW Configurator

affected
1.011M and prior

Mitsubishi Electric Corporation

Data Transfer

affected
3.44W and prior

Mitsubishi Electric Corporation

EZSocket

affected
5.4 and prior

Mitsubishi Electric Corporation

FR Configurator

affected
all versions

Mitsubishi Electric Corporation

FR Configurator SW3

affected
all versions

Mitsubishi Electric Corporation

FR Configurator2

affected
1.24A and prior

Mitsubishi Electric Corporation

GT Designer3 Version1(GOT1000)

affected
1.250L and prior

Mitsubishi Electric Corporation

GT Designer3 Version1(GOT2000)

affected
1.250L and prior

Mitsubishi Electric Corporation

GT SoftGOT1000 Version3

affected
3.245F and prior

Mitsubishi Electric Corporation

GT SoftGOT2000 Version1

affected
1.250L and prior

Mitsubishi Electric Corporation

GX Configurator-DP

affected
7.14Q and prior

Mitsubishi Electric Corporation

GX Configurator-QP

affected
all versions

Mitsubishi Electric Corporation

GX Developer

affected
8.506C and prior

Mitsubishi Electric Corporation

GX Explorer

affected
all versions

Mitsubishi Electric Corporation

GX IEC Developer

affected
all versions

Mitsubishi Electric Corporation

GX LogViewer

affected
1.115U and prior

Mitsubishi Electric Corporation

GX RemoteService-I

affected
all versions

Mitsubishi Electric Corporation

GX Works2

affected
1.597X and prior

Mitsubishi Electric Corporation

GX Works3

affected
1.070Y and prior

Mitsubishi Electric Corporation

iQ Monozukuri ANDON (Data Transfer)

affected
1.003D and prior

Mitsubishi Electric Corporation

iQ Monozukuri Process Remote Monitoring (Data Transfer)

affected
1.002C and prior

Mitsubishi Electric Corporation

M_CommDTM-HART

affected
all versions

Mitsubishi Electric Corporation

M_CommDTM-IO-Link

affected
1.03D and prior

Mitsubishi Electric Corporation

MELFA-Works

affected
4.4 and prior

Mitsubishi Electric Corporation

MELSEC WinCPU Setting Utility

affected
all versions

Mitsubishi Electric Corporation

MELSOFT EM Software Development Kit (EM Configurator)

affected
1.015R and prior

Mitsubishi Electric Corporation

MELSOFT Navigator

affected
2.74C and prior

Mitsubishi Electric Corporation

MH11 SettingTool Version2

affected
2.004E and prior

Mitsubishi Electric Corporation

MI Configurator

affected
1.004E and prior

Mitsubishi Electric Corporation

MT Works2

affected
1.167Z and prior

Mitsubishi Electric Corporation

MX Component

affected
5.001B and prior

Mitsubishi Electric Corporation

Network Interface Board CC IE Control utility

affected
1.29F and prior

Mitsubishi Electric Corporation

Network Interface Board CC IE Field Utility

affected
1.16S and prior

Mitsubishi Electric Corporation

Network Interface Board CC-Link Ver.2 Utility

affected
1.23Z and prior

Mitsubishi Electric Corporation

Network Interface Board MNETH utility

affected
34L and prior

Mitsubishi Electric Corporation

PX Developer

affected
1.53F and prior

Mitsubishi Electric Corporation

RT ToolBox2

affected
3.73B and prior

Mitsubishi Electric Corporation

RT ToolBox3

affected
1.82L and prior

Mitsubishi Electric Corporation

Setting/monitoring tools for the C Controller module (SW4PVC-CCPU)

affected
4.12N and prior

Mitsubishi Electric Corporation

SLMP Data Collector

affected
1.04E and prior

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now