← Vulnerability feed

Vulnerability record · CVE-2020-5603 · published 30 June 2020

CVE-2020-5603: Mitsubishielectric cpu module logging configuration tool uncontrolled resource consumption vulnerability

Mitsubishielectric · Cpu Module Logging Configuration Tool

Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX LogViewer Ver. 1.96A and earlier, GX Works2 Ver. 1.586L and earlier, GX Works3 Ver. 1.058L and earlier, M_CommDTM-HART Ver. 1.00A, M_CommDTM-IO-Link Ver. 1.02C and earlier, MELFA-Works Ver. 4.3 and earlier, MELSEC-L Flexible High-Speed I/O Control Module Configuration Tool Ver.1.004E and earlier, MELSOFT FieldDeviceConfigurator Ver. 1.03D and earlier, MELSOFT iQ AppPortal Ver. 1.11M and earlier, MELSOFT Navigator Ver. 2.58L and earlier, MI Configurator Ver. 1.003D and earlier, Motion Control Setting Ver. 1.005F and earlier, MR Configurator2 Ver. 1.72A and earlier, MT Works2 Ver. 1.156N and earlier, RT ToolBox2 Ver. 3.72A and earlier, and RT ToolBox3 Ver. 1.50C and earlier) allows an attacker to cause a denial of service (DoS) condition attacks via unspecified vectors.

7.5 CVSS 3.1 High EPSS 1.3% · top 30.0% CWE-400 · Uncontrolled resource consumption
7.5CVSS 3.1 base score, v2 5.0
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
20Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX LogViewer Ver. 1.96A and earlier, GX Works2 Ver. 1.586L and earlier, GX Works3 Ver. 1.058L and earlier, M_CommDTM-HART Ver. 1.00A, M_CommDTM-IO-Link Ver. 1.02C and earlier, MELFA-Works Ver. 4.3 and earlier, MELSEC-L Flexible High-Speed I/O Control Module Configuration Tool Ver.1.004E and earlier, MELSOFT FieldDeviceConfigurator Ver. 1.03D and earlier, MELSOFT iQ AppPortal Ver. 1.11M and earlier, MELSOFT Navigator Ver. 2.58L and earlier, MI Configurator Ver. 1.003D and earlier, Motion Control Setting Ver. 1.005F and earlier, MR Configurator2 Ver. 1.72A and earlier, MT Works2 Ver. 1.156N and earlier, RT ToolBox2 Ver. 3.72A and earlier, and RT ToolBox3 Ver. 1.50C and earlier) allows an attacker to cause a denial of service (DoS) condition attacks via unspecified vectors.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

20 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-5603 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-14496Mitsubishielectric cpu module logging configuration tool vulnerabilitySuccessful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions c…EPSS 0.85%9.8CVE-2020-14521Mitsubishielectric c controller interface module utility unquoted search path vulnerabilityMultiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker cou…EPSS 1.3%9.8CVE-2020-14523Mitsubishielectric cw configurator path traversal vulnerabilityMultiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.EPSS 2.3%9.8CVE-2021-20588Mitsubishielectric c controller module setting and monitoring tool memory buffer overflow vulnerabilityImproper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration To…EPSS 6.9%9.8CVE-2021-20587Mitsubishielectric c controller module setting and monitoring tool heap-based buffer overflow vulnerabilityHeap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and pr…EPSS 3.9%7.8CVE-2024-25086Jungo windriver code injection vulnerabilityImproper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code.EPSS 0.34%7.8CVE-2024-25088Jungo windriver improper privilege management vulnerabilityImproper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code.EPSS 0.18%7.8CVE-2024-26314Jungo windriver improper privilege management vulnerabilityImproper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and execute arbitrary code.EPSS 0.23%

Source: NIST National Vulnerability Database (record CVE-2020-5603), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.