CVE-2021-20606
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
17/12/2021
Last modified:
02/02/2023
Description
Out-of-bounds Read vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior, Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior and Mitsubishi Electric EZSocket versions 5.4 and prior allows an attacker to cause a DoS condition in the software by getting a user to open malicious project file specially crafted by an attacker.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mitsubishielectric:ezsocket:*:*:*:*:*:*:*:* | 5.4 (including) | |
| cpe:2.3:a:mitsubishielectric:gx_works2:*:*:*:*:*:*:*:* | 1.606g (including) | |
| cpe:2.3:a:mitsubishielectric:melsoft_navigator:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



