# ICS Advisory (ICSA-20-212-04)
## Mitsubishi Electric Factory Automation Engineering Products
Original release date: July 30, 2020
[Print Document](javascript:window.print\(\);)
[Tweet](https://twitter.com/share?url=https%3A%2F%2Fus-
cert.cisa.gov%2Fics%2Fadvisories%2Ficsa-20-212-04)
[Like Me](https://www.facebook.com/sharer.php?u=https%3A%2F%2Fus-
cert.cisa.gov%2Fics%2Fadvisories%2Ficsa-20-212-04)
[Share](http://www.addthis.com/bookmark.php?url=https%3A%2F%2Fus-
cert.cisa.gov%2Fics%2Fadvisories%2Ficsa-20-212-04)
### Legal Notice
All information products included in [https://us-cert.gov/ics](/ics) are
provided "as is" for informational purposes only. The Department of Homeland
Security (DHS) does not provide any warranties of any kind regarding any
information contained within. DHS does not endorse any commercial product or
service, referenced in this product or otherwise. Further dissemination of
this product is governed by the Traffic Light Protocol (TLP) marking in the
header. For more information about TLP, see [https://www.us-
cert.gov/tlp/](/tlp/).
* * *
## 1\. EXECUTIVE SUMMARY
* **CVSS v3 8.3**
* **ATTENTION:** Low skill level to exploit
* **Vendor:** Mitsubishi Electric
* **Equipment:** Mitsubishi Electric, Factory Automation Engineering products
* **Vulnerability:** Unquoted Search Path or Element
## 2\. RISK EVALUATION
Successful exploitation of this vulnerability may allow an attacker to obtain
unauthorized information, modify information, and cause a denial-of-service
condition.
## 3\. TECHNICAL DETAILS
### 3.1 AFFECTED PRODUCTS
The following products and versions are affected:
* C Controller Interface Module Utility, all versions
* C Controller Module Setting and Monitoring Tool, all versions
* CC-Link IE Control Network Data Collector, all versions
* CC-Link IE Field Network Data Collector, all versions
* CPU Module Logging Configuration Tool, Versions 1.100E and prior
* CW Configurator, Versions 1.010L and prior
* Data Transfer, all versions
* EZSocket, all versions
* FR Configurator SW3, all versions
* FR Configurator2, all versions
* GT Designer2 Classic, all versions
* GT Designer3 Version1 (GOT1000), all versions
* GT Designer3 Version1 (GOT2000), all versions
* GT SoftGOT1000 Version3, all versions
* GT SoftGOT2000 Version1, all versions
* GX Developer, Versions 8.504A and prior
* GX LogViewer, Versions 1.100E and prior
* GX Works2, all versions
* GX Works3, Versions 1.063R and prior
* M_CommDTM-IO-Link, all versions
* MELFA-Works, all versions
* MELSEC WinCPU Setting Utility, all versions
* MELSOFT Complete Clean Up Tool, all versions
* MELSOFT EM Software Development Kit, all versions
* MELSOFT iQ AppPortal, all versions
* MELSOFT Navigator, all versions
* MI Configurator, all versions
* Motion Control Setting, Versions 1.005F and prior
* Motorizer, Versions 1.005F and prior
* MR Configurator2, all versions
* MT Works2, all versions
* MTConnect Data Collector, all versions
* MX Component, all versions
* MX MESInterface, all versions
* MX MESInterface-R, all versions
* MX Sheet, all versions
* Network Interface Board CC IE Control Utility, all versions
* Network Interface Board CC IE Field Utility, all versions
* Network Interface Board CC-Link Ver.2 Utility, all versions
* Network Interface Board MNETH Utility, all versions
* Position Board utility 2, all versions
* PX Developer, all versions
* RT ToolBox2, all versions
* RT ToolBox3, all versions
* Setting/monitoring tools for the C Controller module, all versions
* SLMP Data Collector, all versions
### 3.2 VULNERABILITY OVERVIEW
#### 3.2.1 [UNQUOTED SEARCH PATH OR ELEMENT
CWE-428](https://cwe.mitre.org/data/definitions/428.html)
Multiple Mitsubishi Electric Factory Automation engineering software products
have a malicious code execution vulnerability. A malicious attacker could use
this vulnerability to obtain information, modify information, and cause a
denial-of-service condition.
[CVE-2020-14521](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-14521)
has been assigned to this vulnerability. A CVSS v3 base score of 8.3 has been
calculated; the CVSS vector string is
([AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H](https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)).
### 3.3 BACKGROUND
* **CRITICAL INFRASTRUCTURE SECTORS:** Critical Manufacturing
* **COUNTRIES/AREAS DEPLOYED:** Worldwide
* **COMPANY HEADQUARTERS LOCATION:** Japan
### 3.4 RESEARCHER
Mashav Sapir of Claroty reported this vulnerability to CISA.
## 4\. MITIGATIONS
Mitsubishi Electric recommends the following mitigations:
Download the [latest version](https://www.mitsubishielectric.com/fa/#software)
of each software product and update it. The fixed software products and
versions are as follows:
* CPU Module Logging Configuration Tool, Version 1.106K or later
* CW Configurator, Version 1.011M or later
* GX Developer, Version 8.505B or later
* GX LogViewer, Version 1.106K or later
* GX Works3, Version 1.065T or later
* Motion Control Setting, Version 1.006G or later
* Motorizer, Version 1.010L or later
Refer to the manual for help to update your product.
For users of a product that has not released a fixed version or who cannot
immediately update the product, Mitsubishi Electric recommends taking the
following mitigation measures to minimize risk:
* If a "File Name Warning" message is displayed when starting Windows, take appropriate measures according to the instructions in the message (such as changing a file name) and then install or operate the products.
* Operate the products under an account that does not have administrator privileges.
* Install an antivirus software in computers using the products.
* Restrict network exposure for all control system devices or systems to the minimum necessary and ensure they are not accessible from untrusted networks and hosts.
* Locate control system networks and remote devices behind firewalls and isolate them from the network.
* Use virtual private network (VPN) when remote access is required.
Additional information about the vulnerabilities or Mitsubishi Electric's
compensating control is available by contacting a [Mitsubishi Electric
representative](https://us.mitsubishielectric.com/fa/en/about-
us/distributors).
CISA reminds organizations to perform proper impact analysis and risk
assessment prior to deploying defensive measures.
CISA also provides a section for [control systems security recommended
practices](https://www.us-cert.gov/ics/recommended-practices) on the ICS
webpage on [us-cert.gov](https://www.us-cert.gov/ics). Several recommended
practices are available for reading and download, including [Improving
Industrial Control Systems Cybersecurity with Defense-in-Depth
Strategies](https://www.us-
cert.gov/sites/default/files/recommended_practices/NCCIC_ICS-
CERT_Defense_in_Depth_2016_S508C.pdf).
Additional mitigation guidance and recommended practices are publicly
available on the [ICS webpage on us-cert.gov](https://www.us-cert.gov/ics) in
the Technical Information Paper, [ICS-TIP-12-146-01B--Targeted Cyber Intrusion
Detection and Mitigation Strategies](https://www.us-cert.gov/ics/tips/ICS-
TIP-12-146-01B).
Organizations observing any suspected malicious activity should follow their
established internal procedures and report their findings to CISA for tracking
and correlation against other incidents.
CISA also recommends users take the following measures to protect themselves
from social engineering attacks:
* Do not click web links or open unsolicited attachments in email messages.
* Refer to [Recognizing and Avoiding Email Scams](https://www.us-cert.gov/sites/default/files/publications/emailscams_0905.pdf) for more information on avoiding email scams.
* Refer to [Avoiding Social Engineering and Phishing Attacks](https://www.us-cert.gov/ncas/tips/ST04-014) for more information on social engineering attacks.
No known public exploits specifically target this vulnerability.
暂无评论