Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.
Conclusion & alert: CVE-2020-14523 is rated Moderate Risk (62.1/100): CVSS High severity, with medium exploitation likelihood (EPSS 2.17%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 1.26% | 2.17% | +0.91% |
| 2 | 2025-03-30 | 2.64% | 1.26% | -1.38% |
| 3 | 2025-03-29 | — | 2.64% | — |
Full EPSS history (14 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.3 | 3.1 | HIGH |
|
1.6 | 6.0 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| mitsubishielectric | cw_configurator | <= 1.010l | cpe:2.3:a:mitsubishielectric:cw_configurator:*:*:*:*:*:*:*:* |
| mitsubishielectric | fr_configurator2 | <= 1.22y | cpe:2.3:a:mitsubishielectric:fr_configurator2:*:*:*:*:*:*:*:* |
| mitsubishielectric | gx_works2 | <= 1.595v | cpe:2.3:a:mitsubishielectric:gx_works2:*:*:*:*:*:*:*:* |
| mitsubishielectric | gx_works3 | <= 1.063r | cpe:2.3:a:mitsubishielectric:gx_works3:*:*:*:*:*:*:*:* |
| mitsubishielectric | iu_configuration_tool | <= 1.04 | cpe:2.3:a:mitsubishielectric:iu_configuration_tool:*:*:*:*:*:*:*:* |
| mitsubishielectric | iu_developer2 | <= 1.08 | cpe:2.3:a:mitsubishielectric:iu_developer2:*:*:*:*:*:*:*:* |
| mitsubishielectric | melsoft_iq_appportal | <= 1.17t | cpe:2.3:a:mitsubishielectric:melsoft_iq_appportal:*:*:*:*:*:*:*:* |
| mitsubishielectric | melsoft_navigator | <= 2.70y | cpe:2.3:a:mitsubishielectric:melsoft_navigator:*:*:*:*:*:*:*:* |
| mitsubishielectric | mi_configurator | — | cpe:2.3:a:mitsubishielectric:mi_configurator:*:*:*:*:*:*:*:* |
| mitsubishielectric | mr_configurator2 | <= 1.110q | cpe:2.3:a:mitsubishielectric:mr_configurator2:*:*:*:*:*:*:*:* |
| mitsubishielectric | mt_works2 | <= 1.156n | cpe:2.3:a:mitsubishielectric:mt_works2:*:*:*:*:*:*:*:* |
| mitsubishielectric | mx_component | <= 4.20w | cpe:2.3:a:mitsubishielectric:mx_component:*:*:*:*:*:*:*:* |
| mitsubishielectric | rt_toolbox3 | <= 1.70y | cpe:2.3:a:mitsubishielectric:rt_toolbox3:*:*:*:*:*:*:*:* |
| mitsubishielectric | rd78g4_firmware | <= 10 | cpe:2.3:o:mitsubishielectric:rd78g4_firmware:*:*:*:*:*:*:*:* |
| mitsubishielectric | rd78g8_firmware | <= 10 | cpe:2.3:o:mitsubishielectric:rd78g8_firmware:*:*:*:*:*:*:*:* |
| mitsubishielectric | rd78g16_firmware | <= 10 | cpe:2.3:o:mitsubishielectric:rd78g16_firmware:*:*:*:*:*:*:*:* |
| mitsubishielectric | rd78g32_firmware | <= 10 | cpe:2.3:o:mitsubishielectric:rd78g32_firmware:*:*:*:*:*:*:*:* |
| mitsubishielectric | rd78g64_firmware | <= 10 | cpe:2.3:o:mitsubishielectric:rd78g64_firmware:*:*:*:*:*:*:*:* |
| mitsubishielectric | rd78ghv_firmware | <= 10 | cpe:2.3:o:mitsubishielectric:rd78ghv_firmware:*:*:*:*:*:*:*:* |
| mitsubishielectric | rd78ghw_firmware | <= 10 | cpe:2.3:o:mitsubishielectric:rd78ghw_firmware:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://jvn.jp/vu/JVNVU90224831/ | Third Party Advisory |
| https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-03 | Patch Third Party Advisory US Government Resource |
| https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-008_en.pdf | Vendor Advisory |