CVE Vulnerabilities

CVE-2022-29833

Insufficiently Protected Credentials

Published: Nov 25, 2022 | Modified: May 31, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Insufficiently Protected Credentials vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated users could access to MELSEC safety CPU modules illgally.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Gx_works3 Mitsubishielectric 1.015r (including) 1.086q (including)
Gx_works3 Mitsubishielectric 1.087r (including) *

Potential Mitigations

References