QID 591282

QID 591282: Mitsubishi Electric FA Engineering Software Products Denial-Of-Service condition (DoS) (Update G) (ICSA-21-049-02)

AFFECTED PRODUCTS
The following products and versions are affected:
FR Configurator SW3 All versions
M_CommDTM-IO-Link Versions 1.03D and prior
M_CommDTM-HART All versions
FR Configurator2 Versions 1.24A and prior
MI Configurator Versions 1.004E and prior
GX Developer Versions 8.506C and prior
CW Configurator Versions 1.011M and prior
Setting/monitoring tools for the C Controller module Versions 4.12N and prior
Network Interface Board CC IE Control utility Versions 1.29F and prior
Network Interface Board CC IE Field Utility Versions 1.16S and prior
Network Interface Board MNETH utility Versions 34L and prior

QID Detection Logic (Authenticated)
This QID checks for the Vulnerable version using windows registry keys.

Successful exploitation of these vulnerabilities may cause a denial of service condition.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-049-02 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591282

    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-049-02 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-21-049-02