CVE Vulnerabilities

CVE-2023-5247

Externally Controlled Reference to a Resource in Another Sphere

Published: Nov 30, 2023 | Modified: Dec 05, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software Products allows a malicious attacker to execute a malicious code by having legitimate users open a specially crafted project file, which could result in information disclosure, tampering and deletion, or a denial-of-service (DoS) condition.

Weakness

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

Affected Software

Name Vendor Start Version End Version
Melsoft_navigator Mitsubishielectric * *
Gx_works3 Mitsubishielectric * *
Melsoft_iq_appportal Mitsubishielectric * *
Motion_control_setting Mitsubishielectric * *

References