Path traversal in Mitsubishi Electric products - CVE-2020-14523

 

Path traversal in Mitsubishi Electric products - CVE-2020-14523

Published: July 31, 2020


Vulnerability identifier: #VU32954
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14523
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system, leading to arbitrary code execution.


Affected software

CW Configurator
Mitsubishi Electric FR Configurator2
RT ToolBox3
GX Works2
GX Works3
MT Works2
MELSOFT iQ AppPortal
MELSOFT Navigator
MI Configurator
MR Configurator2
MX Component
MELSEC iQ-R series

How to mitigate CVE-2020-14523

Install update from vendor's website.

CW Configurator - update to 1.011M
Mitsubishi Electric FR Configurator2 - update to 1.23Z
RT ToolBox3 - update to 1.80J
GX Works2 - update to 1.596W
GX Works3 - update to 1.065T
MT Works2 - update to 1.160S

External References

Related Security Bulletins