Heap-Based Buffer Overflow in Mitsubishi Electric FA Engineering Software
CVE-2021-20587
Key Information:
- Status
- Vendor
- CVE Published:
- 19 February 2021
Summary
A heap-based buffer overflow vulnerability identified in Mitsubishi Electric's FA Engineering Software allows remote unauthenticated attackers to potentially disrupt software functionality and cause denial of service (DoS) conditions. The flaw may enable an attacker to execute harmful programs on the underlying personal computer by sending specially crafted packets that spoof the MELSEC, GOT, or FREQROL systems. Without proper mitigations, organizations using affected versions are left at risk.
Affected Version(s)
FA Engineering Software CPU Module Logging Configuration Tool versions 1.112R and prior
FA Engineering Software CW Configurator versions 1.011M and prior
FA Engineering Software Data Transfer versions 3.44W and prior
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved