Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2020-5602

7.5 · HIGH
Published Jun 30, 2020 mitsubishielectric CWE-611 EPSS 1.43% (71th pctl)

Overview

CVE-2020-5602 is a high-severity vulnerability affecting mitsubishielectric cpu_module_logging_configuration_tool. It was published on June 30, 2020 and has a CVSS 3.1 base score of 7.5 (HIGH).

This vulnerability has a CVSS 3.1 base score of 7.5, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX LogViewer Ver. 1.96A and earlier, GX Works2 Ver. 1.586L and earlier, GX Works3 Ver. 1.058L and earlier, M_CommDTM-HART Ver. 1.00A, M_CommDTM-IO-Link Ver. 1.02C and earlier, MELFA-Works Ver. 4.3 and earlier, MELSEC-L Flexible High-Speed I/O Control Module Configuration Tool Ver.1.004E and earlier, MELSOFT FieldDeviceConfigurator Ver. 1.03D and earlier, MELSOFT iQ AppPortal Ver. 1.11M and earlier, MELSOFT Navigator Ver. 2.58L and earlier, MI Configurator Ver. 1.003D and earlier, Motion Control Setting Ver. 1.005F and earlier, MR Configurator2 Ver. 1.72A and earlier, MT Works2 Ver. 1.156N and earlier, RT ToolBox2 Ver. 3.72A and earlier, and RT ToolBox3 Ver. 1.50C and earlier) allows an attacker to conduct XML External Enti

Remediation

Check the references section for vendor advisories and patches from mitsubishielectric. Update cpu_module_logging_configuration_tool to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
mitsubishielectric cpu_module_logging_configuration_tool 0 Affected
mitsubishielectric cw_configurator 0 Affected
mitsubishielectric em_configurator 0 Affected
mitsubishielectric gt_designer3 0 Affected
mitsubishielectric gx_logviewer 0 Affected
mitsubishielectric gx_works2 0 Affected
mitsubishielectric gx_works3 0 Affected
mitsubishielectric m_commdtm-hart 0 Affected
mitsubishielectric m_commdtm-io-link 0 Affected
mitsubishielectric melfa-works 0 Affected
mitsubishielectric melsec-l_flexible_high-speed_i\/o_control_module_configuration_tool 0 Affected
mitsubishielectric melsoft_fielddeviceconfigurator 0 Affected
mitsubishielectric melsoft_iq_appportal 0 Affected
mitsubishielectric melsoft_navigator 0 Affected
mitsubishielectric mi_configurator 0 Affected
mitsubishielectric motion_control_setting 0 Affected
mitsubishielectric mr_configurator2 0 Affected
mitsubishielectric mt_works2 0 Affected
mitsubishielectric rt_toolbox2 0 Affected
mitsubishielectric rt_toolbox3 0 Affected

Frequently Asked Questions

What is CVE-2020-5602?

CVE-2020-5602 is a high-severity vulnerability affecting mitsubishielectric cpu_module_logging_configuration_tool. It was published on June 30, 2020 and has a CVSS 3.1 base score of 7.5 (HIGH).

How severe is CVE-2020-5602?

This vulnerability has a CVSS 3.1 base score of 7.5, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2020-5602?

Check the references section for vendor advisories and patches from mitsubishielectric. Update cpu_module_logging_configuration_tool to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2020-5602?

CyberStrike's AI-powered security agents can automatically detect CVE-2020-5602 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.