Mitsubishielectric
Mitsubishielectric GX Works3: vulnerabilidades y CVE
Mitsubishielectric GX Works3 tiene 34 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE34
Últimos 12 meses1
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-15688 | Crítica (9.2) | 0.12% | — | 17 sept 2026 | Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an invalid block password by… |
| CVE-2024-26314 | Alta (7.8) | 0.23% | — | 2 jul 2024 | Improper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and execute arbitrary code. |
| CVE-2024-25088 | Alta (7.8) | 0.18% | — | 2 jul 2024 | Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code. |
| CVE-2024-25087 | Media (5.5) | 0.25% | — | 2 jul 2024 | Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.7.0 allows local attackers to cause a Windows blue screen error. |
| CVE-2024-25086 | Alta (7.8) | 0.34% | — | 2 jul 2024 | Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code. |
| CVE-2024-22106 | Alta (7.8) | 0.18% | — | 2 jul 2024 | Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute arbitrary code, or cause a Denial of Service (DoS). |
| CVE-2024-22105 | Media (5.5) | 0.20% | — | 2 jul 2024 | Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error. |
| CVE-2024-22104 | Media (5.5) | 0.23% | — | 2 jul 2024 | Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS). |
| CVE-2024-22103 | Media (5.5) | 0.23% | — | 2 jul 2024 | Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS). |
| CVE-2024-22102 | Media (5.5) | 0.20% | — | 2 jul 2024 | Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error. |
| CVE-2023-51778 | Media (5.5) | 0.21% | — | 2 jul 2024 | Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS). |
| CVE-2023-51777 | Media (5.5) | 0.20% | — | 2 jul 2024 | Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error. |
| CVE-2023-51776 | Alta (7.8) | 0.19% | — | 2 jul 2024 | Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code. |
| CVE-2023-6943 | Crítica (9.8) | 2.1% | — | 30 ene 2024 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versions 1.325P and… |
| CVE-2023-6942 | Alta (7.5) | 0.95% | — | 30 ene 2024 | Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versions 1.325P and prior, GT Designer3 Version1(GOT2000)… |
| CVE-2023-5247 | Alta (7.8) | 0.26% | — | 30 nov 2023 | Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software Products allows a malicious attacker to execute a malicious code by having… |
| CVE-2023-4088 | Alta (7.8) | 0.18% | — | 20 sept 2023 | Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products allows a malicious local attacker to execute a malicious code, resulting in information… |
| CVE-2022-29833 | Media (6.5) | 1.0% | — | 25 nov 2022 | Insufficiently Protected Credentials vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later allows a remote unauthenticated attacker to disclose sensitive information. As a result,… |
| CVE-2022-29832 | Media (6.5) | 0.64% | — | 25 nov 2022 | Cleartext Storage of Sensitive Information in Memory vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later, GX Works2 all versions and GX Developer versions 8.40S and later allows a remote… |
| CVE-2022-29831 | Alta (7.5) | 1.3% | — | 25 nov 2022 | Use of Hard-coded Password vulnerability in Mitsubishi Electric Corporation GX Works3 versions from 1.015R to 1.095Z allows a remote unauthenticated attacker to obtain information about the project file for MELSEC… |
| CVE-2022-29830 | Crítica (9.1) | 1.3% | — | 25 nov 2022 | Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z, and Motion Control Setting(GX Works3 related software) versions from 1.000A to 1.065T allows a remote… |
| CVE-2022-29829 | Alta (7.5) | 1.1% | — | 25 nov 2022 | Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.090U, GT Designer3 Version1 (GOT2000) versions from 1.122C to 1.290C, Motion Control Setting(GX Works3 related… |
| CVE-2022-29828 | Alta (7.5) | 1.1% | — | 25 nov 2022 | Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated… |
| CVE-2022-29827 | Alta (7.5) | 1.1% | — | 25 nov 2022 | Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated… |
| CVE-2022-29826 | Alta (7.5) | 0.73% | — | 25 nov 2022 | Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.087R and Motion Control Setting(GX Works3 related software) versions from 1.000A to 1.042U allows a… |
| CVE-2022-29825 | Alta (7.5) | 0.49% | — | 25 nov 2022 | Use of Hard-coded Password vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.090U, GT Designer3 Version1 (GOT2000) versions from 1.122C to 1.290C, and MT Works2 versions from 1.100E to 1.200J… |
| CVE-2022-25164 | Alta (7.5) | 0.85% | — | 25 nov 2022 | Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z and Mitsubishi Electric MX OPC UA Module Configurator-R versions 1.08J and prior allows a remote… |
| CVE-2020-14496 | Crítica (9.8) | 0.85% | — | 19 may 2022 | Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious… |
| CVE-2020-14523 | Crítica (9.8) | 2.3% | — | 11 feb 2022 | Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code. |
| CVE-2020-14521 | Crítica (9.8) | 1.3% | — | 11 feb 2022 | Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information,… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.