CVE-2021-20588

Summary

CVECVE-2021-20588
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2021-02-19 20:15:00 UTC
Updated2023-10-18 00:15:00 UTC
DescriptionImproper handling of length parameter inconsistency vulnerability in Mitsubishi Electric FA Engineering Software(CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3 all versions, FR Configurator2 versions 1.24A and prior, GT Designer3 Version1(GOT1000) versions 1.250L and prior, GT Designer3 Version1(GOT2000) versions 1.250L and prior, GT SoftGOT1000 Version3 versions 3.245F and prior, GT SoftGOT2000 Version1 versions 1.250L and prior, GX Configurator-DP versions 7.14Q and prior, GX Configurator-QP all versions, GX Developer versions 8.506C and prior, GX Explorer all versions, GX IEC Developer all versions, GX LogViewer versions 1.115U and prior, GX RemoteService-I all versions, GX Works2 versions 1.597X and prior, GX Works3 versions 1.070Y and prior, iQ Monozukuri ANDON (Data Transfer) all versions, iQ Monozukuri Process Remote Monitoring (Data Transfer) all versions, M_CommDTM-HART all versions, M_CommDTM-IO-Link versions 1.03D and prior, MELFA-Works versions 4.4 and prior, MELSEC WinCPU Setting Utility all versions, MELSOFT EM Software Development Kit (EM Configurator) versions 1.015R and prior, MELSOFT Navigator versions 2.74C and prior, MH11 SettingTool Version2 versions 2.004E and prior, MI Configurator versions 1.004E and prior, MT Works2 versions 1.167Z and prior, MX Component versions 5.001B and prior, Network Interface Board CC IE Control utility versions 1.29F and prior, Network Interface Board CC IE Field Utility versions 1.16S and prior, Network Interface Board CC-Link Ver.2 Utility versions 1.23Z and prior, Network Interface Board MNETH utility versions 34L and prior, PX Developer versions 1.53F and prior, RT ToolBox2 versions 3.73B and prior, RT ToolBox3 versions 1.82L and prior, Setting/monitoring tools for the C Controller module (SW4PVC-CCPU) versions 4.12N and prior and SLMP Data Collector versions 1.04E and prior) allows a remote unauthenticated attacker to cause a DoS condition of the software products, and possibly to execute a malicious program on the personal computer running the software products although it has not been reproduced, by spoofing MELSEC, GOT or FREQROL and returning crafted reply packets.

Risk And Classification

Problem Types: CWE-119

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Mitsubishielectric Cpu Module Logging Configuration Tool All All All All
Application Mitsubishielectric Cpu Module Logging Configuration Tool All All All All
Application Mitsubishielectric Cpu Module Logging Configuration Tool All All All All
Application Mitsubishielectric Cw Configurator All All All All
Application Mitsubishielectric Cw Configurator All All All All
Application Mitsubishielectric Cw Configurator All All All All
Application Mitsubishielectric C Controller Module Setting And Monitoring Tool All All All All
Application Mitsubishielectric C Controller Module Setting And Monitoring Tool All All All All
Application Mitsubishielectric Data Transfer All All All All
Application Mitsubishielectric Data Transfer All All All All
Application Mitsubishielectric Data Transfer All All All All
Application Mitsubishielectric Ezsocket All All All All
Application Mitsubishielectric Ezsocket All All All All
Application Mitsubishielectric Fr Configurator All All All All
Application Mitsubishielectric Fr Configurator All All All All
Application Mitsubishielectric Fr Configurator2 All All All All
Application Mitsubishielectric Fr Configurator2 All All All All
Application Mitsubishielectric Fr Configurator2 All All All All
Application Mitsubishielectric Fr Configurator Sw3 All All All All
Application Mitsubishielectric Fr Configurator Sw3 All All All All
Application Mitsubishielectric Gt Designer3 All All All All
Application Mitsubishielectric Gt Got1000 All All All All
Application Mitsubishielectric Gt Got1000 All All All All
Application Mitsubishielectric Gt Got2000 All All All All
Application Mitsubishielectric Gt Got2000 All All All All
Application Mitsubishielectric Gt Softgot1000 All All All All
Application Mitsubishielectric Gt Softgot1000 All All All All
Application Mitsubishielectric Gt Softgot1000 All All All All
Application Mitsubishielectric Gt Softgot2000 All All All All
Application Mitsubishielectric Gt Softgot2000 All All All All
Application Mitsubishielectric Gt Softgot2000 All All All All
Application Mitsubishielectric Gx Configurator-dp All All All All
Application Mitsubishielectric Gx Configurator-qp All All All All
Application Mitsubishielectric Gx Configurator-qp All All All All
Application Mitsubishielectric Gx Developer All All All All
Application Mitsubishielectric Gx Developer All All All All
Application Mitsubishielectric Gx Developer All All All All
Application Mitsubishielectric Gx Explorer All All All All
Application Mitsubishielectric Gx Explorer All All All All
Application Mitsubishielectric Gx Iec Developer All All All All
Application Mitsubishielectric Gx Iec Developer All All All All
Application Mitsubishielectric Gx Logviewer All All All All
Application Mitsubishielectric Gx Logviewer All All All All
Application Mitsubishielectric Gx Logviewer All All All All
Application Mitsubishielectric Gx Remoteservice-i All All All All
Application Mitsubishielectric Gx Remoteservice-i All All All All
Application Mitsubishielectric Gx Works2 All All All All
Application Mitsubishielectric Gx Works3 All All All All
Application Mitsubishielectric Iq Monozukuri Andon - All All All
Application Mitsubishielectric Iq Monozukuri Process Remote Monitoring - All All All
Application Mitsubishielectric Melfa-works All All All All
Application Mitsubishielectric Melfa-works All All All All
Application Mitsubishielectric Melfa-works All All All All
Application Mitsubishielectric Melsec Wincpu Setting Utility All All All All
Application Mitsubishielectric Melsec Wincpu Setting Utility All All All All
Application Mitsubishielectric Melsoft Em Software Development Kit All All All All
Application Mitsubishielectric Melsoft Em Software Development Kit All All All All
Application Mitsubishielectric Melsoft Navigator All All All All
Application Mitsubishielectric Melsoft Navigator All All All All
Application Mitsubishielectric Melsoft Navigator All All All All
Application Mitsubishielectric Mh11 Settingtool Version2 All All All All
Application Mitsubishielectric Mh11 Settingtool Version2 All All All All
Application Mitsubishielectric Mh11 Settingtool Version2 All All All All
Application Mitsubishielectric Mi Configurator All All All All
Application Mitsubishielectric Mi Configurator All All All All
Application Mitsubishielectric Mt Works2 All All All All
Application Mitsubishielectric Mt Works2 All All All All
Application Mitsubishielectric Mt Works2 All All All All
Application Mitsubishielectric Mx Component All All All All
Application Mitsubishielectric Mx Component All All All All
Application Mitsubishielectric Mx Component All All All All
Application Mitsubishielectric M Commdtm-hart All All All All
Application Mitsubishielectric M Commdtm-hart All All All All
Application Mitsubishielectric M Commdtm-io-link All All All All
Application Mitsubishielectric M Commdtm-io-link All All All All
Application Mitsubishielectric Network Interface Board Cc-link All All All All
Application Mitsubishielectric Network Interface Board Cc-link All All All All
Application Mitsubishielectric Network Interface Board Cc Ie Control Utility All All All All
Application Mitsubishielectric Network Interface Board Cc Ie Control Utility All All All All
Application Mitsubishielectric Network Interface Board Cc Ie Field Utility All All All All
Application Mitsubishielectric Network Interface Board Cc Ie Field Utility All All All All
Application Mitsubishielectric Network Interface Board Mneth Utility All All All All
Application Mitsubishielectric Network Interface Board Mneth Utility All All All All
Application Mitsubishielectric Px Developer All All All All
Application Mitsubishielectric Px Developer All All All All
Application Mitsubishielectric Px Developer All All All All
Application Mitsubishielectric Rt Toolbox2 All All All All
Application Mitsubishielectric Rt Toolbox2 All All All All
Application Mitsubishielectric Rt Toolbox2 All All All All
Application Mitsubishielectric Rt Toolbox3 All All All All
Application Mitsubishielectric Rt Toolbox3 All All All All
Application Mitsubishielectric Rt Toolbox3 All All All All
Application Mitsubishielectric Setting/monitoring Tools For The C Controller Module All All All All
Application Mitsubishielectric Setting/monitoring Tools For The C Controller Module All All All All
Application Mitsubishielectric Slmp Data Collector All All All All
Application Mitsubishielectric Slmp Data Collector All All All All
Application Mitsubishielectric Slmp Data Collector All All All All

References

ReferenceSourceLinkTags
Mitsubishi Electric FA Engineering Software Products (Update C) | CISA MISC us-cert.cisa.gov
www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-021_en.pdf MISC www.mitsubishielectric.com Vendor Advisory
JVNVU#92330101: 三菱電機製 FA エンジニアリングソフトウェア製品における複数の脆弱性 MISC jvn.jp Third Party Advisory
Mitsubishi Electric FA Engineering Software Products (Update G) | CISA MISC www.cisa.gov
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Legacy QID Mappings

  • 590538 Mitsubishi Electric FA engineering software products (Update B) Multiple Vulnerabilities (ICSA-21-049-02)
  • 590609 Mitsubishi Electric FA Engineering Software Products (Update C) Multiple Vulnerabilities (ICSA-21-049-02)
  • 590623 Mitsubishi Electric FA Engineering Software Products (Update C) Multiple Vulnerabilities (ICSA-21-049-02)
  • 590712 Mitsubishi Electric FA Engineering Software Products (Update D) Multiple Vulnerabilities (ICSA-21-049-02)
  • 591195 Mitsubishi Electric FA Engineering Software Products (Update F) Multiple Vulnerabilities (ICSA-21-049-02)
  • 591282 Mitsubishi Electric FA Engineering Software Products Denial-Of-Service condition (DoS) (Update G) (ICSA-21-049-02)
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report