First published: Wed Sep 20 2023(Updated: )
Incorrect Default Permissions vulnerability due to incomplete fix to address CVE-2020-14496 in Mitsubishi Electric Corporation FA engineering software products allows a malicious local attacker to execute a malicious code, which could result in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition. However, if the mitigated version described in the advisory for CVE-2020-14496 is used and installed in the default installation folder, this vulnerability does not affect the products.
Credit: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishielectric Gx Works3 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-4088.
CVE-2023-4088 has a severity rating of critical (7.8).
CVE-2023-4088 affects Mitsubishi Electric Corporation's FA engineering software product GX Works3.
CVE-2023-4088 may allow a malicious local attacker to execute code, potentially resulting in information disclosure, tampering, or deletion.
More information about CVE-2023-4088 can be found in the [official advisory by Mitsubishi Electric Corporation](https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-010_en.pdf).