First published: Tue Jan 30 2024(Updated: )
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) all versions, GT Designer3 Version1(GOT2000) versions 1.320J and prior, GX Works2 versions 1.11M and later, GX Works3 versions 1.106L and prior, MELSOFT Navigator versions 1.04E to 2.102G, MT Works2 versions 1.190Y and prior, MX Component versions 4.00A to 5.007H and MX OPC Server DA/UA all versions allows a remote unauthenticated attacker to bypass authentication by sending specially crafted packets and connect to the products illegally.
Credit: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishi Electric EZSocket | ||
Mitsubishi Electric GT Designer3 Version1 (GOT1000) | ||
Mitsubishi Electric GT Designer3 Version1 (GOT2000) | ||
Mitsubishi Electric GX Works2 | ||
Mitsubishi Electric GX Works3 | ||
Mitsubishi Electric MELSOFT Navigator | ||
Mitsubishi Electric MT Works2 | ||
Mitsubishi Electric MX Component | ||
Mitsubishi Electric MX OPC Server DA/UA | ||
Mitsubishi Electric EZSocket | >=3.0 | |
Mitsubishi Electric FR Configurator2 Firmware | ||
Mitsubishi Electric GT21 | ||
Mitsubishi Electric GOT2000 Series CC-Link IE TSN Communication Unit | ||
Mitsubishi Electric GX Works2 | >=1.11m | |
Mitsubishi Electric GX Works3 | ||
Mitsubishi Electric MC Works | ||
Mitsubishi Electric iQ Works (MELSOFT Navigator) | >=1.04e | |
Mitsubishi Electric MT Works2 | ||
Mitsubishi Electric MX Component | >=4.00a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6942 has been classified with a high severity due to its missing authentication for critical functions.
To fix CVE-2023-6942, upgrade to the latest versions of the affected Mitsubishi Electric products that address this vulnerability.
CVE-2023-6942 affects EZSocket versions 3.0 to 5.92, GT Designer3 versions, GX Works2 versions, GX Works3 versions, and several others.
Yes, CVE-2023-6942 can be exploited remotely due to the lack of authentication for critical functions.
CVE-2023-6942 is a missing authentication for critical functions vulnerability.