CVE-2021-20588

Description

Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3 all versions, FR Configurator2 versions 1.24A and prior, GT Designer3 Version1(GOT1000) versions 1.250L and prior, GT Designer3 Version1(GOT2000) versions 1.250L and prior, GT SoftGOT1000 Version3 versions 3.245F and prior, GT SoftGOT2000 Version1 versions 1.250L and prior, GX Configurator-DP versions 7.14Q and prior, GX Configurator-QP all versions, GX Developer versions 8.506C and prior, GX Explorer all versions, GX IEC Developer all versions, GX LogViewer versions 1.115U and prior, GX RemoteService-I all versions, GX Works2 versions 1.597X and prior, GX Works3 versions 1.070Y and prior, iQ Monozukuri ANDON (Data Transfer) versions 1.003D and prior, iQ Monozukuri Process Remote Monitoring (Data Transfer) versions 1.002C and prior, M_CommDTM-HART all versions, M_CommDTM-IO-Link versions 1.03D and prior, MELFA-Works versions 4.4 and prior, MELSEC WinCPU Setting Utility all versions, MELSOFT EM Software Development Kit (EM Configurator) versions 1.015R and prior, MELSOFT Navigator versions 2.74C and prior, MH11 SettingTool Version2 versions 2.004E and prior, MI Configurator versions 1.004E and prior, MT Works2 versions 1.167Z and prior, MX Component versions 5.001B and prior, Network Interface Board CC IE Control utility versions 1.29F and prior, Network Interface Board CC IE Field Utility versions 1.16S and prior, Network Interface Board CC-Link Ver.2 Utility versions 1.23Z and prior, Network Interface Board MNETH utility versions 34L and prior, PX Developer versions 1.53F and prior, RT ToolBox2 versions 3.73B and prior, RT ToolBox3 versions 1.82L and prior, Setting/monitoring tools for the C Controller module (SW4PVC-CCPU) versions 4.12N and prior, and SLMP Data Collector versions 1.04E and prior) allows a remote unauthenticated attacker to cause a DoS condition on the software products, and possibly to execute a malicious code on the personal computer running the software products although it has not been reproduced, by spoofing MELSEC, GOT or FREQROL and returning crafted reply packets.

Categories

7.5
CVSS
Severity: High
CVSS 3.1 •
CVSS 2.0 •
EPSS 2.33% Top 20%
Affected: Mitsubishi Electric Corporation CPU Module Logging Configuration Tool
Affected: Mitsubishi Electric Corporation CW Configurator
Affected: Mitsubishi Electric Corporation Data Transfer
Affected: Mitsubishi Electric Corporation EZSocket
Affected: Mitsubishi Electric Corporation FR Configurator
Affected: Mitsubishi Electric Corporation FR Configurator SW3
Affected: Mitsubishi Electric Corporation FR Configurator2
Affected: Mitsubishi Electric Corporation GT Designer3 Version1(GOT1000)
Affected: Mitsubishi Electric Corporation GT Designer3 Version1(GOT2000)
Affected: Mitsubishi Electric Corporation GT SoftGOT1000 Version3
Affected: Mitsubishi Electric Corporation GT SoftGOT2000 Version1
Affected: Mitsubishi Electric Corporation GX Configurator-DP
Affected: Mitsubishi Electric Corporation GX Configurator-QP
Affected: Mitsubishi Electric Corporation GX Developer
Affected: Mitsubishi Electric Corporation GX Explorer
Affected: Mitsubishi Electric Corporation GX IEC Developer
Affected: Mitsubishi Electric Corporation GX LogViewer
Affected: Mitsubishi Electric Corporation GX RemoteService-I
Affected: Mitsubishi Electric Corporation GX Works2
Affected: Mitsubishi Electric Corporation GX Works3
Affected: Mitsubishi Electric Corporation iQ Monozukuri ANDON (Data Transfer)
Affected: Mitsubishi Electric Corporation iQ Monozukuri Process Remote Monitoring (Data Transfer)
Affected: Mitsubishi Electric Corporation M_CommDTM-HART
Affected: Mitsubishi Electric Corporation M_CommDTM-IO-Link
Affected: Mitsubishi Electric Corporation MELFA-Works
Affected: Mitsubishi Electric Corporation MELSEC WinCPU Setting Utility
Affected: Mitsubishi Electric Corporation MELSOFT EM Software Development Kit (EM Configurator)
Affected: Mitsubishi Electric Corporation MELSOFT Navigator
Affected: Mitsubishi Electric Corporation MH11 SettingTool Version2
Affected: Mitsubishi Electric Corporation MI Configurator
Affected: Mitsubishi Electric Corporation MT Works2
Affected: Mitsubishi Electric Corporation MX Component
Affected: Mitsubishi Electric Corporation Network Interface Board CC IE Control utility
Affected: Mitsubishi Electric Corporation Network Interface Board CC IE Field Utility
Affected: Mitsubishi Electric Corporation Network Interface Board CC-Link Ver.2 Utility
Affected: Mitsubishi Electric Corporation Network Interface Board MNETH utility
Affected: Mitsubishi Electric Corporation PX Developer
Affected: Mitsubishi Electric Corporation RT ToolBox2
Affected: Mitsubishi Electric Corporation RT ToolBox3
Affected: Mitsubishi Electric Corporation Setting/monitoring tools for the C Controller module (SW4PVC-CCPU)
Affected: Mitsubishi Electric Corporation SLMP Data Collector
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2021-20588?
CVE-2021-20588 has been scored as a high severity vulnerability.
How to fix CVE-2021-20588?
To fix CVE-2021-20588, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2021-20588 being actively exploited in the wild?
It is possible that CVE-2021-20588 is being exploited or will be exploited in a near future based on public information. According to its EPSS score, there is a ~2% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2021-20588?
CVE-2021-20588 affects Mitsubishi Electric Corporation CPU Module Logging Configuration Tool, Mitsubishi Electric Corporation CW Configurator, Mitsubishi Electric Corporation Data Transfer, Mitsubishi Electric Corporation EZSocket, Mitsubishi Electric Corporation FR Configurator, Mitsubishi Electric Corporation FR Configurator SW3, Mitsubishi Electric Corporation FR Configurator2, Mitsubishi Electric Corporation GT Designer3 Version1(GOT1000), Mitsubishi Electric Corporation GT Designer3 Version1(GOT2000), Mitsubishi Electric Corporation GT SoftGOT1000 Version3, Mitsubishi Electric Corporation GT SoftGOT2000 Version1, Mitsubishi Electric Corporation GX Configurator-DP, Mitsubishi Electric Corporation GX Configurator-QP, Mitsubishi Electric Corporation GX Developer, Mitsubishi Electric Corporation GX Explorer, Mitsubishi Electric Corporation GX IEC Developer, Mitsubishi Electric Corporation GX LogViewer, Mitsubishi Electric Corporation GX RemoteService-I, Mitsubishi Electric Corporation GX Works2, Mitsubishi Electric Corporation GX Works3, Mitsubishi Electric Corporation iQ Monozukuri ANDON (Data Transfer), Mitsubishi Electric Corporation iQ Monozukuri Process Remote Monitoring (Data Transfer), Mitsubishi Electric Corporation M_CommDTM-HART, Mitsubishi Electric Corporation M_CommDTM-IO-Link, Mitsubishi Electric Corporation MELFA-Works, Mitsubishi Electric Corporation MELSEC WinCPU Setting Utility, Mitsubishi Electric Corporation MELSOFT EM Software Development Kit (EM Configurator), Mitsubishi Electric Corporation MELSOFT Navigator, Mitsubishi Electric Corporation MH11 SettingTool Version2, Mitsubishi Electric Corporation MI Configurator, Mitsubishi Electric Corporation MT Works2, Mitsubishi Electric Corporation MX Component, Mitsubishi Electric Corporation Network Interface Board CC IE Control utility, Mitsubishi Electric Corporation Network Interface Board CC IE Field Utility, Mitsubishi Electric Corporation Network Interface Board CC-Link Ver.2 Utility, Mitsubishi Electric Corporation Network Interface Board MNETH utility, Mitsubishi Electric Corporation PX Developer, Mitsubishi Electric Corporation RT ToolBox2, Mitsubishi Electric Corporation RT ToolBox3, Mitsubishi Electric Corporation Setting/monitoring tools for the C Controller module (SW4PVC-CCPU), Mitsubishi Electric Corporation SLMP Data Collector.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.