Description
Insufficiently Protected Credentials vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated users could access to MELSEC safety CPU modules illgally.
Related CPE's
a
mitsubishielectric
gx_works3
2
References
https://jvn.jp/vu/JVNVU97244961
Third Party AdvisoryVDB Entry
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-015_en.pdf
MitigationVendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
6.5 · Medium
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Modified
Published
2022-11-25T00:15:10.580
2 years agoLast modified
2023-05-31T07:15:10.850
2 years ago