First published: Thu Nov 24 2022(Updated: )
Use of Hard-coded Password vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.090U and GT Designer3 Version1 (GOT2000) versions from 1.122C to 1.290C allows an unauthenticated attacker to disclose sensitive information. As a result, unauthenticated users may view programs and project files or execute programs illegally.
Credit: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishi Electric GX Works3 | >=1.000a<=1.011m | |
Mitsubishi Electric GX Works3 | >=1.015r<=1.086q | |
Mitsubishi Electric GX Works3 | >=1.087r | |
Mitsubishi Electric GX Works3: 1.000A to 1.011M (affected by CVE-2022-25164, CVE-2022-29825, CVE-2022-29826, CVE-2022-29827, CVE-2022-29828, CVE-2022-29829, CVE-2022-29830) 1.015R to 1.087R (affected by CVE-2022-25164, CVE-2022-29825, CVE-2022-29826, CVE-2022-29827, CVE-2022-29828, CVE-2022-29829, CVE-2022-29830, CVE-2022-29831, CVE-2022-29832, CVE-2022-29833) 1.090U (affected by CVE-2022-25164, CVE-2022-29825, CVE-2022-29827, CVE-2022-29828, CVE-2022-29829, CVE-2022-29830, CVE-2022-29831, CVE-2022-29832, CVE-2022-29833) --------- Begin Update B Part 1 of 2 --------- 1.095Z (affected by CVE-2022-25164, CVE-2022-29827, CVE-2022-29828, CVE-2022-29830, CVE-2022-29831, CVE-2022-29832, CVE-2022-29833) 1.096A and later (affected by CVE-2022-29827, CVE-2022-29828, CVE-2022-29832, CVE-2022-29833) | ||
Mitsubishi Electric 1.000A to 1.011M | ||
Mitsubishi Electric 1.015R to 1.087R (affected by CVE-2022-25164, CVE-2022-29825, CVE-2022-29826, CVE-2022-29827, CVE-2022-29828, CVE-2022-29829, CVE-2022-29830, CVE-2022-29831, CVE-2022-29832, CVE-2022-29833) | ||
Mitsubishi Electric 1.090U (affected by CVE-2022-25164, CVE-2022-29825, CVE-2022-29827, CVE-2022-29828, CVE-2022-29829, CVE-2022-29830, CVE-2022-29831, CVE-2022-29832, CVE-2022-29833) --------- Begin Update B Part 1 of 2 --------- | ||
Mitsubishi Electric 1.095Z | ||
Mitsubishi Electric 1.096A | ||
Mitsubishi Electric MX OPC UA Module Configurator-R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29825 is a vulnerability that exists in Mitsubishi Electric GX Works3 versions from 1.000A to 1.090U and GT Designer3 Version1 (GOT2000) versions from 1.122C to 1.290C.
The severity of CVE-2022-29825 is high with a CVSS score of 7.5.
CVE-2022-29825 allows an unauthenticated attacker to disclose sensitive information, allowing unauthenticated users to view programs and gain unauthorized access.
Mitsubishi Electric GX Works3 versions from 1.000A to 1.090U and GT Designer3 Version1 (GOT2000) versions from 1.122C to 1.290C are affected by CVE-2022-29825.
To mitigate the CVE-2022-29825 vulnerability, update Mitsubishi Electric GX Works3 to a version higher than 1.090U and GT Designer3 Version1 (GOT2000) to a version higher than 1.290C.