目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

CVE-2021-20587— Mitsubishi Electric FA engineering software 缓冲区错误漏洞

CVSS 7.5 · High EPSS 11.75% · P94
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2021-20587の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
N/A
ソース: NVD (National Vulnerability Database)
脆弱性説明
Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3 all versions, FR Configurator2 versions 1.24A and prior, GT Designer3 Version1(GOT1000) versions 1.250L and prior, GT Designer3 Version1(GOT2000) versions 1.250L and prior, GT SoftGOT1000 Version3 versions 3.245F and prior, GT SoftGOT2000 Version1 versions 1.250L and prior, GX Configurator-DP versions 7.14Q and prior, GX Configurator-QP all versions, GX Developer versions 8.506C and prior, GX Explorer all versions, GX IEC Developer all versions, GX LogViewer versions 1.115U and prior, GX RemoteService-I all versions, GX Works2 versions 1.597X and prior, GX Works3 versions 1.070Y and prior, iQ Monozukuri ANDON (Data Transfer) versions 1.003D and prior, iQ Monozukuri Process Remote Monitoring (Data Transfer) versions 1.002C and prior, M_CommDTM-HART all versions, M_CommDTM-IO-Link versions 1.03D and prior, MELFA-Works versions 4.4 and prior, MELSEC WinCPU Setting Utility all versions, MELSOFT EM Software Development Kit (EM Configurator) versions 1.015R and prior, MELSOFT Navigator versions 2.74C and prior, MH11 SettingTool Version2 versions 2.004E and prior, MI Configurator versions 1.004E and prior, MT Works2 versions 1.167Z and prior, MX Component versions 5.001B and prior, Network Interface Board CC IE Control utility versions 1.29F and prior, Network Interface Board CC IE Field Utility versions 1.16S and prior, Network Interface Board CC-Link Ver.2 Utility versions 1.23Z and prior, Network Interface Board MNETH utility versions 34L and prior, PX Developer versions 1.53F and prior, RT ToolBox2 versions 3.73B and prior, RT ToolBox3 versions 1.82L and prior, Setting/monitoring tools for the C Controller module (SW4PVC-CCPU) versions 4.12N and prior, and SLMP Data Collector versions 1.04E and prior) allows a remote unauthenticated attacker to cause a DoS condition on the software products, and possibly to execute a malicious code on the personal computer running the software products although it has not been reproduced, by spoofing MELSEC, GOT or FREQROL and returning crafted reply packets.
ソース: NVD (National Vulnerability Database)
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ソース: NVD (National Vulnerability Database)
脆弱性タイプ
堆缓冲区溢出
ソース: NVD (National Vulnerability Database)
脆弱性タイトル
Mitsubishi Electric FA engineering software 缓冲区错误漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Mitsubishi Electric FA engineering software是日本三菱电机(Mitsubishi Electric)公司的一个工程软件。提供提高设计和调试的效率,减少停机时间和保护数据。 Mitsubishi Electric FA engineering software 存在缓冲区错误漏洞。多款 Mitsubishi Electric FA engineering 软件中存在输入验证错误漏洞。攻击者可能通过欺骗 MELSEC, GOT, or FREQROL 并返回特制的恢复
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
Mitsubishi Electric CorporationCPU Module Logging Configuration Tool 1.112R and prior -
Mitsubishi Electric CorporationCW Configurator 1.011M and prior -
Mitsubishi Electric CorporationData Transfer 3.44W and prior -
Mitsubishi Electric CorporationEZSocket 5.4 and prior -
Mitsubishi Electric CorporationFR Configurator all versions -
Mitsubishi Electric CorporationFR Configurator SW3 all versions -
Mitsubishi Electric CorporationFR Configurator2 1.24A and prior -
Mitsubishi Electric CorporationGT Designer3 Version1(GOT1000) 1.250L and prior -
Mitsubishi Electric CorporationGT Designer3 Version1(GOT2000) 1.250L and prior -
Mitsubishi Electric CorporationGT SoftGOT1000 Version3 3.245F and prior -
Mitsubishi Electric CorporationGT SoftGOT2000 Version1 1.250L and prior -
Mitsubishi Electric CorporationGX Configurator-DP 7.14Q and prior -
Mitsubishi Electric CorporationGX Configurator-QP all versions -
Mitsubishi Electric CorporationGX Developer 8.506C and prior -
Mitsubishi Electric CorporationGX Explorer all versions -
Mitsubishi Electric CorporationGX IEC Developer all versions -
Mitsubishi Electric CorporationGX LogViewer 1.115U and prior -
Mitsubishi Electric CorporationGX RemoteService-I all versions -
Mitsubishi Electric CorporationGX Works2 1.597X and prior -
Mitsubishi Electric CorporationGX Works3 1.070Y and prior -
Mitsubishi Electric CorporationiQ Monozukuri ANDON (Data Transfer) 1.003D and prior -
Mitsubishi Electric CorporationiQ Monozukuri Process Remote Monitoring (Data Transfer) 1.002C and prior -
Mitsubishi Electric CorporationM_CommDTM-HART all versions -
Mitsubishi Electric CorporationM_CommDTM-IO-Link 1.03D and prior -
Mitsubishi Electric CorporationMELFA-Works 4.4 and prior -
Mitsubishi Electric CorporationMELSEC WinCPU Setting Utility all versions -
Mitsubishi Electric CorporationMELSOFT EM Software Development Kit (EM Configurator) 1.015R and prior -
Mitsubishi Electric CorporationMELSOFT Navigator 2.74C and prior -
Mitsubishi Electric CorporationMH11 SettingTool Version2 2.004E and prior -
Mitsubishi Electric CorporationMI Configurator 1.004E and prior -
Mitsubishi Electric CorporationMT Works2 1.167Z and prior -
Mitsubishi Electric CorporationMX Component 5.001B and prior -
Mitsubishi Electric CorporationNetwork Interface Board CC IE Control utility 1.29F and prior -
Mitsubishi Electric CorporationNetwork Interface Board CC IE Field Utility 1.16S and prior -
Mitsubishi Electric CorporationNetwork Interface Board CC-Link Ver.2 Utility 1.23Z and prior -
Mitsubishi Electric CorporationNetwork Interface Board MNETH utility 34L and prior -
Mitsubishi Electric CorporationPX Developer 1.53F and prior -
Mitsubishi Electric CorporationRT ToolBox2 3.73B and prior -
Mitsubishi Electric CorporationRT ToolBox3 1.82L and prior -
Mitsubishi Electric CorporationSetting/monitoring tools for the C Controller module (SW4PVC-CCPU) 4.12N and prior -
Mitsubishi Electric CorporationSLMP Data Collector 1.04E and prior -

II. CVE-2021-20587の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2021-20587のインテリジェンス情報

お願いします ログイン より多くのインテリジェンス情報を見る

IV. 関連脆弱性

V. CVE-2021-20587へのコメント

まだコメントはありません


コメントを残す