9.8

CVE-2020-14496

Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed, tampered with, and/or destroyed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MitsubishielectricCw Configurator Version < 1.011m
MitsubishielectricData Transfer Version < 3.41t
MitsubishielectricEm Configurator Version < 1.015r
MitsubishielectricEzsocket Version < 4.6
MitsubishielectricGt Designer3 Version < 1.236w
MitsubishielectricGt Softgot1000 Version < 3.245f
MitsubishielectricGt Softgot2000 Version < 1.236w
MitsubishielectricGx Logviewer Version < 1.106k
MitsubishielectricGx Works2 Version < 1.595v
MitsubishielectricGx Works3 Version < 1.065t
MitsubishielectricM Commdtm-hart Version < 1.01b
MitsubishielectricMelfa-works Version < 4.4
MitsubishielectricMotorizer Version < 1.010l
MitsubishielectricMr Configurator2 Version < 1.106l
MitsubishielectricMt Works2 Version < 1.160s
MitsubishielectricMx Component Version < 4.20w
MitsubishielectricPx Developer Version < 1.53f
MitsubishielectricRt Toolbox2 Version < 3.73b
MitsubishielectricRt Toolbox3 Version < 1.80j
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.332
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
ics-cert@hq.dhs.gov 8.3 1.6 6
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.