Security Vulnerabilities fixed in Mitsubishi CW Configurator 2020-021

description-logoDescription

Improper handling of length parameter inconsistency vulnerability in Mitsubishi Electronic CW Configurator version 1.011M and earlier allows a remote unauthenticated attacker to cause a DoS condition of the software products, and possibly to execute a malicious program on the personal computer running the software products although it has not been reproduced, by spoofing MELSEC, GOT or FREQROL and returning crafted reply packets.

affected-products-logoAffected Applications

CW Configurator