CVE-2020-5602 Details
Description
Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX LogViewer Ver. 1.96A and earlier, GX Works2 Ver. 1.586L and earlier, GX Works3 Ver. 1.058L and earlier, M_CommDTM-HART Ver. 1.00A, M_CommDTM-IO-Link Ver. 1.02C and earlier, MELFA-Works Ver. 4.3 and earlier, MELSEC-L Flexible High-Speed I/O Control Module Configuration Tool Ver.1.004E and earlier, MELSOFT FieldDeviceConfigurator Ver. 1.03D and earlier, MELSOFT iQ AppPortal Ver. 1.11M and earlier, MELSOFT Navigator Ver. 2.58L and earlier, MI Configurator Ver. 1.003D and earlier, Motion Control Setting Ver. 1.005F and earlier, MR Configurator2 Ver. 1.72A and earlier, MT Works2 Ver. 1.156N and earlier, RT ToolBox2 Ver. 3.72A and earlier, and RT ToolBox3 Ver. 1.50C and earlier) allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vectors.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/vu/JVNVU90307594/index.html | CVE | Third Party Advisory |
| https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-004_en.pdf | CVE | MitigationVendor Advisory |
| https://jvn.jp/en/vu/JVNVU90307594/index.html | [email protected] | Third Party Advisory |
| https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-004_en.pdf | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mitsubishielectric cpu module logging configuration tool | <= 1.94y |
CPE
Remediation
| |
| mitsubishielectric cw configurator | <= 1.010l |
CPE
Remediation
| |
| mitsubishielectric em configurator | <= 1.010l |
CPE
Remediation
| |
| mitsubishielectric gt designer3 | <= 1.221f |
CPE
Remediation
| |
| mitsubishielectric gx logviewer | <= 1.100e |
CPE
Remediation
| |
| mitsubishielectric gx works2 | <= 1.590q |
CPE
Remediation
| |
| mitsubishielectric gx works3 | <= 1.060n |
CPE
Remediation
| |
| mitsubishielectric m commdtm-hart | <= 1.01b |
CPE
Remediation
| |
| mitsubishielectric m commdtm-io-link | <= 1.03d |
CPE
Remediation
| |
| mitsubishielectric melfa-works | <= 4.4 |
CPE
Remediation
| |
| mitsubishielectric melsec-l flexible high-speed i/o control module configuration tool | <= 1.005f |
CPE
Remediation
| |
| mitsubishielectric melsoft fielddeviceconfigurator | <= 1.04e |
CPE
Remediation
| |
| mitsubishielectric melsoft iq appportal | <= 1.14q |
CPE
Remediation
| |
| mitsubishielectric melsoft navigator | <= 2.62q |
CPE
Remediation
| |
| mitsubishielectric mi configurator | <= 1.004e |
CPE
Remediation
| |
| mitsubishielectric motion control setting | <= 1.006g |
CPE
Remediation
| |
| mitsubishielectric mr configurator2 | <= 1.100e |
CPE
Remediation
| |
| mitsubishielectric mt works2 | <= 1.160s |
CPE
Remediation
| |
| mitsubishielectric rt toolbox2 | <= 3.73b |
CPE
Remediation
| |
| mitsubishielectric rt toolbox3 | <= 1.60n |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jul 14, 2020 | Initial Analysis | [email protected] |