Unauthenticated Access to MELSEC Safety CPU Modules in Mitsubishi Electric Corporation GX Works3

Unauthenticated Access to MELSEC Safety CPU Modules in Mitsubishi Electric Corporation GX Works3

CVE-2022-29833 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Insufficiently Protected Credentials vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated users could access to MELSEC safety CPU modules illgally.

Learn more about our User Device Pen Test.