Hard-coded Cryptographic Key Vulnerability in Mitsubishi Electric GX Works3 and Related Software
CVE-2022-29829

6.8MEDIUM

Summary

The vulnerability allows remote unauthenticated attackers to exploit hard-coded cryptographic keys in various Mitsubishi Electric software, leading to unauthorized access to sensitive programs and project files. This flaw can enable attackers to execute programs illicitly, potentially jeopardizing the operational integrity of the affected systems.

Affected Version(s)

GT Designer3 Version1 (GOT2000) from 1.122C to 1.290C

GX Works3 from 1.000A to 1.090U

Motion Control Setting(GX Works3 related software) from 1.035M to 1.042U

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.