CVE-2023-6942: High severity Mitsubishielectric Ezsocket vulnerability
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versions 1.325P and prior, GT Designer3 Version1(GOT2000) versions 1.320J and prior, GX Works2 versions 1.11M to 1.626C, GX Works3 versions 1.106L and prior, MELSOFT Navigator versions 1.04E to 2.102G, MT Works2 versions 1.190Y and prior, MX Component versions 4.00A to 5.007H and MX OPC Server DA/UA all versions allows a remote unauthenticated attacker to bypass authentication by sending specially crafted packets and connect to the products illegally.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6942?
CVE-2023-6942 has been classified with a high severity due to its missing authentication for critical functions.
How do I fix CVE-2023-6942?
To fix CVE-2023-6942, upgrade to the latest versions of the affected Mitsubishi Electric products that address this vulnerability.
Which versions of Mitsubishi Electric products are affected by CVE-2023-6942?
CVE-2023-6942 affects EZSocket versions 3.0 to 5.92, GT Designer3 versions, GX Works2 versions, GX Works3 versions, and several others.
Can CVE-2023-6942 be exploited remotely?
Yes, CVE-2023-6942 can be exploited remotely due to the lack of authentication for critical functions.
What type of vulnerability is CVE-2023-6942?
CVE-2023-6942 is a missing authentication for critical functions vulnerability.