Rewterz
Rewterz Threat Advisory – CVE-2021-44145 – Apache NiFi Vulnerability
December 20, 2021
Rewterz
Rewterz Threat Advisory – CVE-2021-42278 – Microsoft Windows privilege escalation
December 21, 2021

Rewterz Threat Advisory – ICS: Mitsubishi Electric FA Engineering Software and GX Works2

Severity

High

Analysis Summary

CVE-2021-20608

If an attacker tampers with a program file in a Mitsubishi Electric PLC by sending malicious crafted packets to the PLC, reading the program file into GX Works2, the engineering software incorrectly handles a length field that is inconsistent with the actual length of the associated data, which could result in a denial-of-service condition in the software.

CVE-2021-20607

When a valid user opens a malicious project file specially crafted by an attacker, the product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

CVE-2021-20606

When a valid user opens a malicious project file specially crafted by an attacker, the software reads data outside of the intended buffer, allowing an attacker to potentially cause a denial-of-service condition in the software.

Impact

  • Denial of Service

Affected Vendors

  • Mitsubishi Electric

Affected Products

  • GX Works2: Versions 1.606G and prior
  • MELSOFT Navigator: All versions
  • EZSockdet: All versions

Remediation

Refer to CISA Advisory for the patch, upgrade, or suggested workaround information.

https://www.cisa.gov/uscert/ics/advisories/icsa-21-350-04