← Back to home
ICSA-21-049-02  ·  Published 2025-06-05  ·  View on CISA ICS-CERT ↗

Mitsubishi Electric FA Engineering Software Products (Update H)

CVSS 7.5 HIGH

Risk Summary

Successful exploitation of these vulnerabilities may cause a denial-of-service condition.

Remediations

  • Mitsubishi Electric has released updated versions for the following products to address these vulnerabilities. Please download and install the update from the Mitsubishi Electric download site.:
  • CPU Module Logging Configuration Tool: Version 1.118X or later
  • CW Configurator: Version 1.012N or later
  • Data Transfer: Version 3.45X or later
  • EZSocket: Version 5.5 or later
  • FR Configurator2: Version 1.25B or later
  • GT Designer3 Version1(GOT1000): Version 1.255R or later
  • GT Designer3 Version1(GOT2000): Version 1.255R or later
  • GT SoftGOT1000 Version3: Version 3.255R or later
  • GT SoftGOT2000 Version1: Version 1.255R or later
  • GX Configurator-DP: Version 7.15R or later
  • GX Developer: Version 8.507D or later
  • GX LogViewer: Version 1.118X or later
  • GX Works2: Version 1.600A or later
  • GX Works3: Version 1.072A or later
  • iQ Monozukuri ANDON (Data Transfer): Version 1.004E or later
  • iQ Monozukuri Process Remote Monitoring (Data Transfer): Version 1.005F or later
  • M_CommDTM-IO-Link: Version 1.04E or later
  • MELFA-Works: Version 4.5 or later
  • MELSOFT EM Software Development Kit (EM Configurator): Version 1.020W or later
  • MELSOFT Navigator: Version 2.78G or later
  • MH11 SettingTool Version2: Version 2.005F or later
  • MI Configurator: Version 1.005F or later
  • MT Works2: Version 1.170C or later
  • MX Component: Version 5.002C or later
  • Network Interface Board CC IE Control utility: Version 1.30G or later
  • Network Interface Board CC IE Field Utility: Version 1.17T or later
  • Network Interface Board CC-Link Ver.2 Utility: Version 1.24A or later
  • Network Interface Board MNETH utility: Version 35M or later
  • PX Developer: Version 1.54G or later
  • RT ToolBox2: Version 3.74C or later
  • RT ToolBox3: Version 1.90U or later
  • Setting/monitoring tools for the C Controller module (SW4PVC-CCPU): Version 4.13P or later
  • SLMP Data Collector: Version 1.05F or later
  • Mitsubishi Electric has no plans to release fixed versions for the following products:
  • FR Configurator
  • FR Configurator SW3
  • GX Configurator-QP
  • GX Explorer
  • GX IEC Developer
  • GX RemoteService-I
  • M_CommDTM-HART
  • MELSEC WinCPU Setting Utility
  • For users of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric recommends taking the following mitigations to minimize the risk of exploiting these vulnerabilities:
  • Install the fixed version of GX Works3 on your personal computer running the products when communicating with MELSEC. GX Works3 provides comprehensive countermeasures that provide the same level of protection to other products.
  • Install the fixed version of FR Configurator2 on your personal computer running the products when communicating with FREQROL. FR Configurator2 provides comprehensive countermeasures that provide the same level of protection to other products.
  • Install the fixed version of GT Designer3 on your personal computer running the products when communicating with GOT. GT Designer3 provides comprehensive countermeasures that provide the same level of protection to other products.
  • Operate the products under an account that does not have administrator privileges.
  • Install antivirus software on personal computers running the products.
  • Restrict network exposure for all control system devices or systems to the minimum necessary, and ensure that they are not accessible from untrusted networks and hosts.
  • Locate control system networks and remote devices behind firewalls and isolate them from the business network.
  • Use a virtual private network (VPN) when remote access is required.
  • Refer to Mitsubishi Electric advisory 2020-021 for more information.

Affected Vendors

Mitsubishi Electric

Affected Products (41)

Mitsubishi Electric · CPU Module Logging Configuration Tool <=1.112R
Mitsubishi Electric · CW Configurator <=1.011M
Mitsubishi Electric · Data Transfer <=3.44W
Mitsubishi Electric · EZSocket <=5.4
Mitsubishi Electric · FR Configurator vers:all/*
Mitsubishi Electric · FR Configurator SW3 vers:all/*
Mitsubishi Electric · FR Configurator2 <=1.24A
Mitsubishi Electric · GT Designer3 Version1(GOT1000) <=1.250L
Mitsubishi Electric · GT Designer3 Version1(GOT2000) <=1.250L
Mitsubishi Electric · GT SoftGOT1000 Version3 <=3.245F
Mitsubishi Electric · GT SoftGOT2000 Version1 <=1.250L
Mitsubishi Electric · GX Configurator-DP <=7.14Q
Mitsubishi Electric · GX Configurator-QP vers:all/*
Mitsubishi Electric · GX Developer <=8.506C
Mitsubishi Electric · GX Explorer vers:all/*
Mitsubishi Electric · GX IEC Developer vers:all/*
Mitsubishi Electric · GX LogViewer <=1.115U
Mitsubishi Electric · GX RemoteService-I vers:all/*
Mitsubishi Electric · GX Works2 <=1.597X
Mitsubishi Electric · GX Works3 <=1.070Y
Mitsubishi Electric · iQ Monozukuri ANDON (Data Transfer) <=1.003D
Mitsubishi Electric · iQ Monozukuri Process Remote Monitoring (Data Transfer) <=1.002C
Mitsubishi Electric · M_CommDTM-HART vers:all/*
Mitsubishi Electric · M_CommDTM-IO-Link <=1.03D
Mitsubishi Electric · MELFA-Works <=4.4
Mitsubishi Electric · MELSEC WinCPU Setting Utility vers:all/*
Mitsubishi Electric · MELSOFT EM Software Development Kit (EM Configurator) <=1.015R
Mitsubishi Electric · MELSOFT Navigator <=2.74C
Mitsubishi Electric · MH11 SettingTool Version2 <=2.004E
Mitsubishi Electric · MI Configurator <=1.004E
Mitsubishi Electric · MT Works2 <=1.167Z
Mitsubishi Electric · MX Component <=5.001B
Mitsubishi Electric · Network Interface Board CC IE Control utility <=1.29F
Mitsubishi Electric · Network Interface Board CC IE Field Utility <=1.16S
Mitsubishi Electric · Network Interface Board CC-Link Ver.2 Utility <=1.23Z
Mitsubishi Electric · Network Interface Board MNETH utility <=34L
Mitsubishi Electric · PX Developer <=1.53F
Mitsubishi Electric · RT ToolBox2 <=3.73B
Mitsubishi Electric · RT ToolBox3 <=1.82L
Mitsubishi Electric · Setting/monitoring tools for the C Controller module (SW4PVC-CCPU) <=4.12N
Mitsubishi Electric · SLMP Data Collector <=1.04E

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more