2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2020-14523" ,
"sourceIdentifier" : "ics-cert@hq.dhs.gov" ,
"published" : "2022-02-11T18:15:08.577" ,
"lastModified" : "2022-03-01T16:20:08.000" ,
"vulnStatus" : "Analyzed" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code."
} ,
{
"lang" : "es" ,
"value" : "diversos productos de Mitsubishi Electric Factory Automation presentan una vulnerabilidad que permite a un atacante ejecutar c\u00f3digo arbitrario"
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 9.8 ,
"baseSeverity" : "CRITICAL"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 5.9
} ,
{
"source" : "ics-cert@hq.dhs.gov" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "HIGH" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 8.3 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 1.6 ,
"impactScore" : 6.0
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P" ,
"accessVector" : "NETWORK" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "PARTIAL" ,
"availabilityImpact" : "PARTIAL" ,
"baseScore" : 7.5
} ,
"baseSeverity" : "HIGH" ,
"exploitabilityScore" : 10.0 ,
"impactScore" : 6.4 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-22"
}
]
} ,
{
"source" : "ics-cert@hq.dhs.gov" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-22"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mitsubishielectric:cw_configurator:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "1.010l" ,
"matchCriteriaId" : "892E3CDC-AFC4-4EF1-AF46-3F161603DDB1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mitsubishielectric:fr_configurator2:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "1.22y" ,
"matchCriteriaId" : "87549502-D224-408D-8C66-41F5E8F7743A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mitsubishielectric:gx_works2:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "1.595v" ,
"matchCriteriaId" : "015EB163-A5D6-4C55-8038-59823B7FF49F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mitsubishielectric:gx_works3:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "1.063r" ,
"matchCriteriaId" : "AE537EF6-72AE-4091-AF6E-9959C3F45632"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mitsubishielectric:iu_configuration_tool:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "1.04" ,
"matchCriteriaId" : "83B09E17-9CFF-4231-AE28-FB9D99332BCB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mitsubishielectric:iu_developer2:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "1.08" ,
"matchCriteriaId" : "D449D560-C64A-48B0-B1BB-31800FF3062E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mitsubishielectric:melsoft_iq_appportal:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "1.17t" ,
"matchCriteriaId" : "8F2EA556-367B-4F32-99D2-C685742CCAEE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mitsubishielectric:melsoft_navigator:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "2.70y" ,
"matchCriteriaId" : "FF88C6B0-5641-488E-9AE2-6AF479EB10BF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mitsubishielectric:mi_configurator:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A661B972-912C-4DAA-9518-CC01E0EB1A81"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mitsubishielectric:mr_configurator2:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "1.110q" ,
"matchCriteriaId" : "50DAB8A0-E2F3-496A-B6B6-22E4243D104C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mitsubishielectric:mt_works2:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "1.156n" ,
"matchCriteriaId" : "04FF09A2-B1C0-4A65-A420-22A044B7F2CD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mitsubishielectric:mx_component:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "4.20w" ,
"matchCriteriaId" : "A0C9B5B3-D4F6-4E00-89B4-964516BB989B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mitsubishielectric:rt_toolbox3:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "1.70y" ,
"matchCriteriaId" : "463E3740-A618-45A6-9C30-6FBC28077123"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:mitsubishielectric:rd78g4:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B9B1BA74-5B02-400C-AA98-AFB29E848299"
2023-04-24 12:24:31 +02:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:mitsubishielectric:rd78g4_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "10" ,
"matchCriteriaId" : "BEAB1838-A2E2-4D12-A216-68DD9E4624CF"
2023-04-24 12:24:31 +02:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:mitsubishielectric:rd78g8:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8467C47A-2798-43FA-B132-A774B1148FC0"
2023-04-24 12:24:31 +02:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:mitsubishielectric:rd78g8_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "10" ,
"matchCriteriaId" : "E213C893-9C88-42C1-BE32-634D7BB84AD6"
2023-04-24 12:24:31 +02:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:mitsubishielectric:rd78g16:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5F671BBC-41EE-41FF-87B1-36DBFA7A4BAD"
2023-04-24 12:24:31 +02:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:mitsubishielectric:rd78g16_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "10" ,
"matchCriteriaId" : "389EBE60-F4CF-4E82-975D-44DCBAC74929"
2023-04-24 12:24:31 +02:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:mitsubishielectric:rd78g32:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "81DD3BFA-9E3A-4FAB-AB7B-6CC365628877"
2023-04-24 12:24:31 +02:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:mitsubishielectric:rd78g32_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "10" ,
"matchCriteriaId" : "2325BC60-32F9-46CA-8035-7E88360C15A1"
2023-04-24 12:24:31 +02:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:mitsubishielectric:rd78g64:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F0A92E26-C302-4285-BED1-7B8637E252DA"
2023-04-24 12:24:31 +02:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:mitsubishielectric:rd78g64_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "10" ,
"matchCriteriaId" : "DC759E3E-6D0A-4BA5-AB2E-38947331C5B2"
2023-04-24 12:24:31 +02:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:mitsubishielectric:rd78ghv:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "12E5533D-15A8-471B-899B-FE9F9655EE8F"
2023-04-24 12:24:31 +02:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:mitsubishielectric:rd78ghv_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "10" ,
"matchCriteriaId" : "D70552B7-C943-43B0-B5BD-ED43A853657E"
2023-04-24 12:24:31 +02:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:mitsubishielectric:rd78ghw:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8B5C3119-7579-4623-8513-65A281BDF0D1"
2023-04-24 12:24:31 +02:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:mitsubishielectric:rd78ghw_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "10" ,
"matchCriteriaId" : "BA2C0DCD-65E6-4B93-B92F-E4FE46CCA58C"
2023-04-24 12:24:31 +02:00
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://jvn.jp/vu/JVNVU90224831/" ,
"source" : "ics-cert@hq.dhs.gov" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-03" ,
"source" : "ics-cert@hq.dhs.gov" ,
"tags" : [
"Patch" ,
"Third Party Advisory" ,
"US Government Resource"
]
} ,
{
"url" : "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-008_en.pdf" ,
"source" : "ics-cert@hq.dhs.gov" ,
"tags" : [
"Vendor Advisory"
]
}
]
}