Cleartext Storage of Sensitive Information in Mitsubishi Electric GX Works3 and GX Works2
CVE-2022-29832
3.7LOW
Key Information:
- Vendor
- CVE Published:
- 25 November 2022
What is CVE-2022-29832?
A vulnerability exists in Mitsubishi Electric Corporation's GX Works3, GX Works2, and GX Developer that allows a remote unauthenticated attacker to access sensitive information. This vulnerability arises from the cleartext storage of project file data, potentially exposing sensitive configuration details of MELSEC safety CPU modules and the MELSEC Q/FX/L series. Unauthorized users could exploit this weakness to gain insight into critical project files, raising significant security concerns.
Affected Version(s)
GX Developer 8.40S and later
GX Works2 all versions
GX Works3 1.015R and later