ICSA-20-212-03
·
Published 2021-05-27
·
View on CISA ICS-CERT ↗
Mitsubishi Electric Factory Automation Products Path Traversal (Update C)
CVSS 8.3
HIGH
Risk Summary
Successful exploitation of this vulnerability may allow an attacker to obtain unauthorized information, tamper the information, and cause a denial-of-service condition.
CVEs (1)
Remediations
- CW Configurator: Version 1.011M or later
- FR Configurator2: Version 1.23Z or later
- GX Works2: Version 1.596W or later
- GX Works3: Version 1.065T or later
- MELSEC iQ-R Series Motion Module: Version 12 and later
- MELSOFT iQ AppPortal: Version 1.20W or later
- MELSOFT Navigator: Versions 2.74C or later
- MI Configurator: Versions 1.005F or later
- MR Configurator2: Versions 1.115V or later
- MT Works2: Versions 1.160S or later
- MX Component: Versions 4.21X or later
- RT ToolBox3: Versions 1.80J or later
- Reference Mitsubishi Electric
- Make sure the file is obtained from the correct acquisition route when receiving a project file or a configuration data file from another person via email, USB memory, file server, etc.; or check that there is no file of unknown source.
- Operate the products under an account that does not have administrator privileges. Except for MELSEC iQ-R Series Motion Module.
- Install an antivirus software in computers using the products. Except for MELSEC iQ-R Series Motion Module.
- Restrict network exposure for all control system devices or systems to the minimum necessary and ensure they are not accessible from untrusted networks and hosts.
- Locate control system networks and remote devices behind firewalls and isolate them from the business network.
- Use virtual private network (VPN) when remote access is required.
- Additional information about the vulnerability or Mitsubishi Electric's compensating control is available by contacting a Mitsubishi Electric representative.
Affected Vendors
Mitsubishi Electric
Affected Products (12)
Mitsubishi Electric
·
GX Works2
<= 1.595V
Mitsubishi Electric
·
MT Works2 Versions
<= 1.156N
Mitsubishi Electric
·
MELSEC iQ-R Series Motion Module
<= 10
Mitsubishi Electric
·
FR Configurator2
<= 1.22Y
Mitsubishi Electric
·
CW Configurator
<= 1.010L
Mitsubishi Electric
·
MI Configurator versions
<= 1.004E
Mitsubishi Electric
·
MELSOFT Navigator
<= 2.70Y
Mitsubishi Electric
·
RT ToolBox3 Versions
<= 1.70Y
Mitsubishi Electric
·
GX Works3
<= 1.063R
Mitsubishi Electric
·
MR Configurator2 Version
<= 1.110Q
Mitsubishi Electric
·
MELSOFT iQ AppPortal
<= 1.17T
Mitsubishi Electric
·
MX Component Version
<= 4.20W
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more