First published: Thu Nov 24 2022(Updated: )
Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated attackers may view programs and project file or execute programs illegally.
Credit: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishielectric Gx Works3 | >=1.000a<=1.011m | |
Mitsubishielectric Gx Works3 | >=1.015r<=1.086q | |
Mitsubishielectric Gx Works3 | >=1.087r | |
Mitsubishi Electric 1.096A and later (affected by CVE-2022-29827, CVE-2022-29828, CVE-2022-29832, CVE-2022-29833) | ||
Mitsubishi Electric MX OPC UA Module Configurator-R: 1.08J and prior (affected by CVE-2022-25164) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29828 is a vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later that allows a remote unauthenticated attacker to disclose sensitive information.
An attacker can exploit CVE-2022-29828 by remotely accessing the affected system and viewing programs and project files or executing programs illegally.
CVE-2022-29828 has a severity rating of high, with a CVSS score of 7.5.
Mitsubishi Electric GX Works3 versions from 1.000A to 1.011m and versions from 1.015r to 1.086q are affected by CVE-2022-29828.
To fix CVE-2022-29828, it is recommended to update to a version of Mitsubishi Electric GX Works3 that is not affected by the vulnerability. Refer to the vendor's advisory for patching instructions.