Hard-coded Cryptographic Key Vulnerability in Mitsubishi Electric GX Works3
CVE-2022-29830
9.1CRITICAL
Key Information:
- Vendor
- CVE Published:
- 25 November 2022
Summary
The identified vulnerability within Mitsubishi Electric's GX Works3 software involves the use of hard-coded cryptographic keys, which could allow remote, unauthenticated attackers to gain access to sensitive information. This may lead to the illicit disclosure or alteration of project files. Affected versions include GX Works3 from 1.000A to 1.095Z and related software starting from version 1.000A. Organizations utilizing these products should take immediate action to mitigate the risks associated with this vulnerability.
Affected Version(s)
GX Works3 from 1.000A to 1.095Z
Motion Control Setting(GX Works3 related software) from 1.000A and later
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved