XML External Entity injection in Mitsubishi Electric products - CVE-2020-5602
Published: July 1, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied XML input. A remote attacker can send a specially crafted file on the computer running the product to the outside and view contents of arbitrary files on the system or initiate requests to external systems.
Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.
Affected software
Motion Control Setting
MI Configurator
MELSOFT Navigator
MELSOFT iQ AppPortal
MELSOFT FieldDeviceConfigurator
MELSEC-L Flexible High-Speed I/O Control Module Configuration Tool
MELFA-Works
M_CommDTM-IO-Link
M_CommDTM-HART
MR Configurator2
GX Works3
GX Works2
RT ToolBox2
GX LogViewer
RT ToolBox3
GT Designer3
MT Works2
CW Configurator
EM Software Development Kit
How to mitigate CVE-2020-5602
Motion Control Setting - update to 1.006G
MI Configurator - update to 1.004E
MELSOFT Navigator - update to 2.62Q
MELSOFT iQ AppPortal - update to 1.14Q
MELSOFT FieldDeviceConfigurator - update to 1.04E
MELSEC-L Flexible High-Speed I/O Control Module Configuration Tool - update to 1.005F
MELFA-Works - update to 4.4
M_CommDTM-IO-Link - update to 1.03D
M_CommDTM-HART - update to 1.01 B
MR Configurator2 - update to 1.100E
GX Works3 - update to 1.060N
GX Works2 - update to 1.590Q
RT ToolBox2 - update to 3.73 B
GX LogViewer - update to 1.100E
RT ToolBox3 - update to 1.60N
GT Designer3 - update to 1.225K
MT Works2 - update to 1.160S
CW Configurator - update to 1.011M
EM Software Development Kit - update to 1.015R