Malicious Code Execution Vulnerability in Mitsubishi Electric FA Engineering Software
CVE-2023-5247
Key Information:
- Vendor
- CVE Published:
- 30 November 2023
What is CVE-2023-5247?
A vulnerability exists in multiple Mitsubishi Electric FA Engineering Software products that allows for the external control of file names or paths. This can lead to scenarios where a malicious attacker might execute arbitrary code when a legitimate user opens a specifically crafted project file. The implications of this vulnerability are severe, potentially leading to information disclosure, data tampering, deletion of critical information, or even a denial-of-service (DoS) condition.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GX Works3 all versions
MELSOFT iQ AppPortal all versions
MELSOFT Navigator all versions
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
