Path traversal in Mitsubishi Electric products - CVE-2020-14523
Published: July 31, 2020
Vulnerability identifier: #VU32954
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14523
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system, leading to arbitrary code execution.
Affected software
CW Configurator
Mitsubishi Electric FR Configurator2
RT ToolBox3
GX Works2
GX Works3
MT Works2
MELSOFT iQ AppPortal
MELSOFT Navigator
MI Configurator
MR Configurator2
MX Component
MELSEC iQ-R series
Mitsubishi Electric FR Configurator2
RT ToolBox3
GX Works2
GX Works3
MT Works2
MELSOFT iQ AppPortal
MELSOFT Navigator
MI Configurator
MR Configurator2
MX Component
MELSEC iQ-R series
How to mitigate CVE-2020-14523
Install update from vendor's website.
CW Configurator - update to 1.011M
Mitsubishi Electric FR Configurator2 - update to 1.23Z
RT ToolBox3 - update to 1.80J
GX Works2 - update to 1.596W
GX Works3 - update to 1.065T
MT Works2 - update to 1.160S
Mitsubishi Electric FR Configurator2 - update to 1.23Z
RT ToolBox3 - update to 1.80J
GX Works2 - update to 1.596W
GX Works3 - update to 1.065T
MT Works2 - update to 1.160S