First published: Thu Nov 24 2022(Updated: )
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z and Mitsubishi Electric MX OPC UA Module Configurator-R versions 1.08J and prior allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated attackers can gain unauthorized access to the MELSEC CPU module and the MELSEC OPC UA server module.
Credit: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishi Electric GX Works3 | >=1.000a<=1.011m | |
Mitsubishi Electric GX Works3 | >=1.015r<=1.086q | |
Mitsubishi Electric GX Works3 | >=1.087r | |
Mitsubishi Electric MX OPC UA Module Configurator-R | ||
Mitsubishi Electric GX Works3: 1.000A to 1.011M (affected by CVE-2022-25164, CVE-2022-29825, CVE-2022-29826, CVE-2022-29827, CVE-2022-29828, CVE-2022-29829, CVE-2022-29830) 1.015R to 1.087R (affected by CVE-2022-25164, CVE-2022-29825, CVE-2022-29826, CVE-2022-29827, CVE-2022-29828, CVE-2022-29829, CVE-2022-29830, CVE-2022-29831, CVE-2022-29832, CVE-2022-29833) 1.090U (affected by CVE-2022-25164, CVE-2022-29825, CVE-2022-29827, CVE-2022-29828, CVE-2022-29829, CVE-2022-29830, CVE-2022-29831, CVE-2022-29832, CVE-2022-29833) --------- Begin Update B Part 1 of 2 --------- 1.095Z (affected by CVE-2022-25164, CVE-2022-29827, CVE-2022-29828, CVE-2022-29830, CVE-2022-29831, CVE-2022-29832, CVE-2022-29833) 1.096A and later (affected by CVE-2022-29827, CVE-2022-29828, CVE-2022-29832, CVE-2022-29833) | ||
Mitsubishi Electric 1.000A to 1.011M | ||
Mitsubishi Electric 1.015R to 1.087R (affected by CVE-2022-25164, CVE-2022-29825, CVE-2022-29826, CVE-2022-29827, CVE-2022-29828, CVE-2022-29829, CVE-2022-29830, CVE-2022-29831, CVE-2022-29832, CVE-2022-29833) | ||
Mitsubishi Electric 1.090U (affected by CVE-2022-25164, CVE-2022-29825, CVE-2022-29827, CVE-2022-29828, CVE-2022-29829, CVE-2022-29830, CVE-2022-29831, CVE-2022-29832, CVE-2022-29833) --------- Begin Update B Part 1 of 2 --------- | ||
Mitsubishi Electric 1.095Z | ||
Mitsubishi Electric 1.096A | ||
Mitsubishi Electric MX OPC UA Module Configurator-R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25164 is a vulnerability that allows a remote unauthenticated attacker to disclose sensitive information in Mitsubishi Electric GX Works3 versions 1.000A to 1.095Z and Mitsubishi Electric MX OPC UA Module Configurator-R versions 1.08J and prior.
CVE-2022-25164 has a severity rating of 7.5 (High).
Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z and Mitsubishi Electric MX OPC UA Module Configurator-R versions 1.08J and prior are affected by CVE-2022-25164.
An unauthenticated remote attacker can exploit CVE-2022-25164 to disclose sensitive information.
It is recommended to refer to the official advisories and documentation provided by Mitsubishi Electric for information on available fixes or patches for CVE-2022-25164.