Vulnerabilities > Mitsubishielectric > GX Works2 > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-12-17 CVE-2021-20607 Integer Underflow (Wrap or Wraparound) vulnerability in Mitsubishielectric Ezsocket, GX Works2 and Melsoft Navigator
Integer Underflow vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior, Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior and Mitsubishi Electric EZSocket versions 5.4 and prior allows an attacker to cause a DoS condition in the software by getting a user to open malicious project file specially crafted by an attacker.
local
low complexity
mitsubishielectric CWE-191
5.5
2021-12-17 CVE-2021-20608 Unspecified vulnerability in Mitsubishielectric GX Works2 1.590Q/1.597X
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior allows a remote unauthenticated attacker to cause a DoS condition in GX Works2 by getting GX Works2 to read a tampered program file from a Mitsubishi Electric PLC by sending malicious crafted packets to tamper with the program file.
network
low complexity
mitsubishielectric
5.0
2020-06-30 CVE-2020-5603 Resource Exhaustion vulnerability in Mitsubishielectric products
Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver.
network
low complexity
mitsubishielectric CWE-400
5.0
2020-06-30 CVE-2020-5602 XXE vulnerability in Mitsubishielectric products
Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver.
network
low complexity
mitsubishielectric CWE-611
5.0