First published: Thu Nov 24 2022(Updated: )
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.087R and Motion Control Setting(GX Works3 related software) versions from 1.000A to 1.042U allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated users may view programs and project files or execute programs illegally.
Credit: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishielectric Gx Works3 | >=1.000a<=1.011m | |
Mitsubishielectric Gx Works3 | >=1.015r<=1.086q | |
Mitsubishi Electric 1.096A and later (affected by CVE-2022-29827, CVE-2022-29828, CVE-2022-29832, CVE-2022-29833) | ||
Mitsubishi Electric MX OPC UA Module Configurator-R: 1.08J and prior (affected by CVE-2022-25164) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29826 is a vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting software that allows a remote attacker to disclose sensitive information.
The affected versions of Mitsubishi Electric GX Works3 range from 1.000A to 1.087R, while the affected versions of Motion Control Setting software range from 1.000A to 1.042U.
CVE-2022-29826 has a severity rating of 7.5 (High).
An attacker can exploit CVE-2022-29826 remotely and without authentication to disclose sensitive information.
Yes, Mitsubishi Electric has provided a security advisory with recommendations for mitigating the vulnerability. Please refer to the provided references for more information.