Hard-coded Cryptographic Key Vulnerability in Mitsubishi Electric GX Works3 and Related Software
CVE-2022-29829
6.8MEDIUM
Key Information:
- Vendor
- CVE Published:
- 25 November 2022
Summary
The vulnerability allows remote unauthenticated attackers to exploit hard-coded cryptographic keys in various Mitsubishi Electric software, leading to unauthorized access to sensitive programs and project files. This flaw can enable attackers to execute programs illicitly, potentially jeopardizing the operational integrity of the affected systems.
Affected Version(s)
GT Designer3 Version1 (GOT2000) from 1.122C to 1.290C
GX Works3 from 1.000A to 1.090U
Motion Control Setting(GX Works3 related software) from 1.035M to 1.042U
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved