CVE-2021-20587

Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3 all versions, FR Configurator2 versions 1.24A and prior, GT Designer3 Version1(GOT1000) versions 1.250L and prior, GT Designer3 Version1(GOT2000) versions 1.250L and prior, GT SoftGOT1000 Version3 versions 3.245F and prior, GT SoftGOT2000 Version1 versions 1.250L and prior, GX Configurator-DP versions 7.14Q and prior, GX Configurator-QP all versions, GX Developer versions 8.506C and prior, GX Explorer all versions, GX IEC Developer all versions, GX LogViewer versions 1.115U and prior, GX RemoteService-I all versions, GX Works2 versions 1.597X and prior, GX Works3 versions 1.070Y and prior, iQ Monozukuri ANDON (Data Transfer) versions 1.003D and prior, iQ Monozukuri Process Remote Monitoring (Data Transfer) versions 1.002C and prior, M_CommDTM-HART all versions, M_CommDTM-IO-Link versions 1.03D and prior, MELFA-Works versions 4.4 and prior, MELSEC WinCPU Setting Utility all versions, MELSOFT EM Software Development Kit (EM Configurator) versions 1.015R and prior, MELSOFT Navigator versions 2.74C and prior, MH11 SettingTool Version2 versions 2.004E and prior, MI Configurator versions 1.004E and prior, MT Works2 versions 1.167Z and prior, MX Component versions 5.001B and prior, Network Interface Board CC IE Control utility versions 1.29F and prior, Network Interface Board CC IE Field Utility versions 1.16S and prior, Network Interface Board CC-Link Ver.2 Utility versions 1.23Z and prior, Network Interface Board MNETH utility versions 34L and prior, PX Developer versions 1.53F and prior, RT ToolBox2 versions 3.73B and prior, RT ToolBox3 versions 1.82L and prior, Setting/monitoring tools for the C Controller module (SW4PVC-CCPU) versions 4.12N and prior, and SLMP Data Collector versions 1.04E and prior) allows a remote unauthenticated attacker to cause a DoS condition on the software products, and possibly to execute a malicious code on the personal computer running the software products although it has not been reproduced, by spoofing MELSEC, GOT or FREQROL and returning crafted reply packets.

Published: 2021-02-19 Last update: 2025-06-13 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2021-20587 is rated High Risk (65.5/100): CVSS High severity, with high exploitation likelihood (EPSS 11.75%, 94th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +2.75% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2021-20587

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-02-21 9.01% 11.75% +2.75%
2 2025-11-24 4.49% 9.01% +4.51%
3 2025-11-21 4.49%

Full EPSS history (22 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2021-20587

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.5 3.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 3.6 [email protected]
9.8 3.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 5.9 [email protected]
7.5 2.0 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
10.0 6.4 [email protected]

Weakness enumeration for CVE-2021-20587

Affected software / configurations for CVE-2021-20587

Vendor Product Version Raw CPE
mitsubishielectric c_controller_module_setting_and_monitoring_tool cpe:2.3:a:mitsubishielectric:c_controller_module_setting_and_monitoring_tool:*:*:*:*:*:*:*:*
mitsubishielectric cpu_module_logging_configuration_tool <= 1.112r cpe:2.3:a:mitsubishielectric:cpu_module_logging_configuration_tool:*:*:*:*:*:*:*:*
mitsubishielectric cw_configurator <= 1.011m cpe:2.3:a:mitsubishielectric:cw_configurator:*:*:*:*:*:*:*:*
mitsubishielectric data_transfer <= 3.44w cpe:2.3:a:mitsubishielectric:data_transfer:*:*:*:*:*:*:*:*
mitsubishielectric ezsocket cpe:2.3:a:mitsubishielectric:ezsocket:*:*:*:*:*:*:*:*
mitsubishielectric fr_configurator cpe:2.3:a:mitsubishielectric:fr_configurator:*:*:*:*:*:*:*:*
mitsubishielectric fr_configurator_sw3 cpe:2.3:a:mitsubishielectric:fr_configurator_sw3:*:*:*:*:*:*:*:*
mitsubishielectric fr_configurator2 <= 1.24a cpe:2.3:a:mitsubishielectric:fr_configurator2:*:*:*:*:*:*:*:*
mitsubishielectric gt_designer3 <= 1.250l cpe:2.3:a:mitsubishielectric:gt_designer3:*:*:*:*:*:*:*:*
mitsubishielectric gt_softgot1000 <= 3.245f cpe:2.3:a:mitsubishielectric:gt_softgot1000:*:*:*:*:*:*:*:*
mitsubishielectric gt_softgot2000 <= 1.250l cpe:2.3:a:mitsubishielectric:gt_softgot2000:*:*:*:*:*:*:*:*
mitsubishielectric gx_configurator-dp <= 7.14q cpe:2.3:a:mitsubishielectric:gx_configurator-dp:*:*:*:*:*:*:*:*
mitsubishielectric gx_configurator-qp cpe:2.3:a:mitsubishielectric:gx_configurator-qp:*:*:*:*:*:*:*:*
mitsubishielectric gx_developer <= 8.506c cpe:2.3:a:mitsubishielectric:gx_developer:*:*:*:*:*:*:*:*
mitsubishielectric gx_explorer cpe:2.3:a:mitsubishielectric:gx_explorer:*:*:*:*:*:*:*:*
mitsubishielectric gx_iec_developer cpe:2.3:a:mitsubishielectric:gx_iec_developer:*:*:*:*:*:*:*:*
mitsubishielectric gx_logviewer <= 1.115u cpe:2.3:a:mitsubishielectric:gx_logviewer:*:*:*:*:*:*:*:*
mitsubishielectric gx_remoteservice-i cpe:2.3:a:mitsubishielectric:gx_remoteservice-i:*:*:*:*:*:*:*:*
mitsubishielectric gx_works2 <= 1.597x cpe:2.3:a:mitsubishielectric:gx_works2:*:*:*:*:*:*:*:*
mitsubishielectric gx_works3 <= 1.070y cpe:2.3:a:mitsubishielectric:gx_works3:*:*:*:*:*:*:*:*
mitsubishielectric iq_monozukuri_andon cpe:2.3:a:mitsubishielectric:iq_monozukuri_andon:-:*:*:*:*:*:*:*
mitsubishielectric iq_monozukuri_process_remote_monitoring cpe:2.3:a:mitsubishielectric:iq_monozukuri_process_remote_monitoring:-:*:*:*:*:*:*:*
mitsubishielectric m_commdtm-hart cpe:2.3:a:mitsubishielectric:m_commdtm-hart:*:*:*:*:*:*:*:*
mitsubishielectric m_commdtm-io-link cpe:2.3:a:mitsubishielectric:m_commdtm-io-link:*:*:*:*:*:*:*:*
mitsubishielectric melfa-works <= 4.4 cpe:2.3:a:mitsubishielectric:melfa-works:*:*:*:*:*:*:*:*
mitsubishielectric melsec_wincpu_setting_utility cpe:2.3:a:mitsubishielectric:melsec_wincpu_setting_utility:*:*:*:*:*:*:*:*
mitsubishielectric melsoft_em_software_development_kit cpe:2.3:a:mitsubishielectric:melsoft_em_software_development_kit:*:*:*:*:*:*:*:*
mitsubishielectric melsoft_navigator <= 2.74c cpe:2.3:a:mitsubishielectric:melsoft_navigator:*:*:*:*:*:*:*:*
mitsubishielectric mh11_settingtool_version2 <= 2.004e cpe:2.3:a:mitsubishielectric:mh11_settingtool_version2:*:*:*:*:*:*:*:*
mitsubishielectric mi_configurator cpe:2.3:a:mitsubishielectric:mi_configurator:*:*:*:*:*:*:*:*
mitsubishielectric mt_works2 <= 1.167z cpe:2.3:a:mitsubishielectric:mt_works2:*:*:*:*:*:*:*:*
mitsubishielectric mx_component <= 5.001b cpe:2.3:a:mitsubishielectric:mx_component:*:*:*:*:*:*:*:*
mitsubishielectric network_interface_board_cc-link cpe:2.3:a:mitsubishielectric:network_interface_board_cc-link:*:*:*:*:*:*:*:*
mitsubishielectric network_interface_board_cc_ie_control_utility cpe:2.3:a:mitsubishielectric:network_interface_board_cc_ie_control_utility:*:*:*:*:*:*:*:*
mitsubishielectric network_interface_board_cc_ie_field_utility cpe:2.3:a:mitsubishielectric:network_interface_board_cc_ie_field_utility:*:*:*:*:*:*:*:*
mitsubishielectric network_interface_board_mneth_utility cpe:2.3:a:mitsubishielectric:network_interface_board_mneth_utility:*:*:*:*:*:*:*:*
mitsubishielectric px_developer <= 1.53f cpe:2.3:a:mitsubishielectric:px_developer:*:*:*:*:*:*:*:*
mitsubishielectric rt_toolbox2 <= 3.73b cpe:2.3:a:mitsubishielectric:rt_toolbox2:*:*:*:*:*:*:*:*
mitsubishielectric rt_toolbox3 <= 1.82l cpe:2.3:a:mitsubishielectric:rt_toolbox3:*:*:*:*:*:*:*:*
mitsubishielectric setting\/monitoring_tools_for_the_c_controller_module cpe:2.3:a:mitsubishielectric:setting\/monitoring_tools_for_the_c_controller_module:*:*:*:*:*:*:*:*
mitsubishielectric slmp_data_collector <= 1.04e cpe:2.3:a:mitsubishielectric:slmp_data_collector:*:*:*:*:*:*:*:*

References for CVE-2021-20587

cvelogic Threat Intelligence