← Back to home
ICSA-20-212-02  ·  Published 2022-09-30  ·  View on CISA ICS-CERT ↗

ICSA-20-212-02_Mitsubishi Electric Multiple Factory Automation Engineering Software Products (Update A)

CVSS 8.3 HIGH

CVEs (1)

Remediations

  • Download the latest version of each software product and update it
  • EZSocket is a communication middleware product for Mitsubishi Electric partner companies. Mitsubishi Electric will directly provide the fixed version to the partner companies.
  • Download and update the latest FR Configurator2 fixed version.
  • Mitsubishi Electric recommends users migrate to the MELSEC iQ-R series MELSEC WinCPU module, which uses the settings tool CW Configurator (SW1DND-RCCPU-E). The settings tool for MELSEC-Q series WinCPU module, MELSEC WinCPU Setting Utility, will not receive a patched version.
  • Mitsubishi Electric has provided firmware updates for the following products to fix the vulnerability. Refer to the manual for update help. See Mitsubishi Electric's security advisory for more details.
  • CPU Module Logging Configuration Tool, Version 1.106K or later
  • CW Configurator, Version 1.011M or later
  • Data Transfer, Version 3.41T or later
  • EZSocket, Version 4.6 or later
  • FR Configurator2, Version 1.23Z or later
  • GT Designer3 Version1 (GOT2000), Version 1.236W or later
  • GT SoftGOT1000 Version3, Version 3.245F or later
  • GT SoftGOT2000 Version1, Version 1.236W or later
  • GX LogViewer, Version 1.106K or later
  • GX Works2, Version 1.595V or later
  • GX Works3, Version 1.065T or later
  • M_CommDTM-HART, Version 1.01B or later
  • M_CommDTM-IO-Link, Versions 1.04E or later
  • MELFA-Works, Version 4.4 or later
  • MELSOFT EM Software Development Kit (EM Configurator), Version 1.015R or later
  • MELSOFT FieldDeviceConfigurator, Version 1.04E or later
  • MELSOFT Navigator, Version 2.70Y or later
  • MH11 SettingTool Version2, Version 2.003D or later
  • MI Configurator, Version 1.005F or later
  • Motorizer, Version 1.010L or later
  • MR Configurator2, Version 1.106L or later
  • MT Works2, Version 1.160S or later
  • MX Component, Version 4.20W or later
  • Network Interface Board CC IE Control utility, Version 1.30G or later
  • Network Interface Board CC IE Field Utility, Version 1.17T or later
  • Network Interface Board CC-Link Ver.2 Utility, Version 1.24A or later
  • Network Interface Board MNETH utility, Version 35M or later
  • PX Developer, Version 1.53F or later
  • RT ToolBox2, Version 3.73B or later
  • RT ToolBox3, Version 1.80J or later
  • Setting/monitoring tools for the C Controller module (SW4PVC-CCPU), Version 4.13P or later
  • Install the fixed version GX Works2, GX Works3, or MELSOFT Navigator on the PC on which the product is installed. This is because these three products provide comprehensive countermeasures that give the same countermeasure effect to other products installed in the same folder (e.g. C:\Program files\MELSOFT).
  • Operate the products under an account that does not have administrator's privileges.
  • Install an antivirus software in computers using the products.
  • Restrict network exposure for all control system devices or systems to the minimum necessary and ensure they are not accessible from untrusted networks and hosts.
  • Locate control system networks and remote devices behind firewalls and isolate them from the network.
  • Use virtual private network (VPN) when remote access is required.
  • Additional information about the vulnerability or the Mitsubishi Electric compensating control is available by contacting a Mitsubishi Electric representative.

Affected Vendors

Mitsubishi Electric

Affected Products (33)

Mitsubishi Electric · Data Transfer <= 3.40S
Mitsubishi Electric · MELSOFT FieldDeviceConfigurator <= 1.03D
Mitsubishi Electric · GT SoftGOT2000 Version1 Bersions <= 1.235V
Mitsubishi Electric · MR Configurator2 <= 1.105K
Mitsubishi Electric · FR Configurator2 <= 1.22Y
Mitsubishi Electric · PX Developer <= 1.52E
Mitsubishi Electric · M_CommDTM-HART 1.00A
Mitsubishi Electric · MELSEC WinCPU Setting Utility <= 1.03D
Mitsubishi Electric · MELSEC WinCPU Setting Utility <=1.03D
Mitsubishi Electric · CPU Module Logging Configuration Tool <= 1.100E
Mitsubishi Electric · GT SoftGOT1000 Version3 vers:all/*
Mitsubishi Electric · Setting/monitoring tools for the C Controller module (SW4PVC-CCPU) <= 4.12N
Mitsubishi Electric · MH11 SettingTool Version2 <= 2.002C
Mitsubishi Electric · Motorizer <= 1.005F
Mitsubishi Electric · GX Works2 <= 1.592S
Mitsubishi Electric · EZSocket <= 4.5
Mitsubishi Electric · GX LogViewer <= 1.100E
Mitsubishi Electric · CW Configurator <= 1.010L
Mitsubishi Electric · Network Interface Board CC IE Control utility <= 1.29F
Mitsubishi Electric · MELSOFT EM Software Development Kit (EM Configurator) <= 1.010L
Mitsubishi Electric · Network Interface Board MNETH utility <= 34L
Mitsubishi Electric · M_CommDTM-IO-Link <= 1.03D
Mitsubishi Electric · GT SoftGOT1000 Version3 <= 3.200J
Mitsubishi Electric · MELSOFT Navigator <= 2.62Q
Mitsubishi Electric · Network Interface Board CC-Link Ver.2 Utility <= 1.23Z
Mitsubishi Electric · MELFA-Works <= 4.3
Mitsubishi Electric · MX Component <= 4.19V
Mitsubishi Electric · GX Works3 <= 1.063R
Mitsubishi Electric · RT ToolBox2 <= 3.72A
Mitsubishi Electric · Network Interface Board CC IE Field Utility <= 1.16S
Mitsubishi Electric · RT ToolBox3 <= 1.70Y
Mitsubishi Electric · MI Configurator <= 1.004E
Mitsubishi Electric · MT Works2 <= 1.156N

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more