HomeSecurityFlaws identified in Mitsubishi automation products

Defects found in Mitsubishi automation products

Security researchers have discovered a number of serious flaws in Mitsubishi Electric 's factory automation products , which could be exploited by malicious actors to remotely attack organizations.

Mitsubishi

As the U.S. Cybersecurity and Infrastructure Security Agency (CISA) reported last week, dozens of Mitsubishi Electric factory automation products are affected by three flaws that can be exploited for privilege escalation, arbitrary code execution, and DoS attacks .

Mitsubishi has already released patches for many of the affected products and is also providing mitigation methods for the rest, as well as for customers who are unable to install the updates immediately.

Cybersecurity firm Claroty was the one who uncovered the flaws at Mitsubishi in late 2019 and early 2020 as part of a research into ICS project files. Claroty recently released an open-source tool that allows researchers to analyze Microsoft Access database files associated with SCADA applications .

Defects found in Mitsubishi automation products

The Claroty researcher who discovered these vulnerabilities, Mashav Sapir, said he discovered the flaws in one of the products, which had been used by a customer, but applauded Mitsubishi for providing a full list of the affected products.

Sapir noted that one of the flaws, CVE-2020-14523, can be exploited remotely by tricking a user into opening a specially crafted file, via a phishing attack.

An attacker could exploit this vulnerability to drop a malicious executable file on the target system and then exploit the other two bugs, CVE-2020-14496 or CVE-2020-14521 to execute that file with elevated privileges.

“An attacker who successfully exploited these vulnerabilities would gain full access and control over the computer running Mitsubishi’s engineering software,” the researcher explained. “This means they have full access to both the configuration of the ICS devices and the ability to change it at will, as well as full network access to those devices, so they also have the ability to attack them directly. This means the attacker can now compromise the operation of the OT environment, modifying it or disrupting it completely, without detection.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS