Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.
                
            References
                    | Link | Resource | 
|---|---|
| https://jvn.jp/vu/JVNVU90224831/ | Third Party Advisory | 
| https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-03 | Patch Third Party Advisory US Government Resource | 
| https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-008_en.pdf | Vendor Advisory | 
| https://jvn.jp/vu/JVNVU90224831/ | Third Party Advisory | 
| https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-03 | Patch Third Party Advisory US Government Resource | 
| https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-008_en.pdf | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
Configuration 2 (hide)
| AND | 
            
            
 
  | 
    
Configuration 3 (hide)
| AND | 
            
            
 
  | 
    
Configuration 4 (hide)
| AND | 
            
            
 
  | 
    
Configuration 5 (hide)
| AND | 
            
            
 
  | 
    
Configuration 6 (hide)
| AND | 
            
            
 
  | 
    
Configuration 7 (hide)
| AND | 
            
            
 
  | 
    
Configuration 8 (hide)
| AND | 
            
            
 
  | 
    
History
                    21 Nov 2024, 05:03
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://jvn.jp/vu/JVNVU90224831/ - Third Party Advisory | |
| References | () https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-03 - Patch, Third Party Advisory, US Government Resource | |
| References | () https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-008_en.pdf - Vendor Advisory | |
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : 7.5
         v3 : 8.3  | 
Information
                Published : 2022-02-11 18:15
Updated : 2024-11-21 05:03
NVD link : CVE-2020-14523
Mitre link : CVE-2020-14523
CVE.ORG link : CVE-2020-14523
JSON object : View
Products Affected
                mitsubishielectric
- mr_configurator2
 - rd78g32
 - rd78ghv
 - melsoft_navigator
 - gx_works2
 - rt_toolbox3
 - rd78ghw_firmware
 - rd78g32_firmware
 - iu_developer2
 - mx_component
 - rd78ghw
 - rd78g64_firmware
 - melsoft_iq_appportal
 - rd78g8
 - rd78g16_firmware
 - iu_configuration_tool
 - cw_configurator
 - mi_configurator
 - rd78g8_firmware
 - rd78g4_firmware
 - rd78g64
 - gx_works3
 - rd78ghv_firmware
 - fr_configurator2
 - rd78g16
 - rd78g4
 - mt_works2
 
CWE
                
                    
                        
                        CWE-22
                        
            Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
