
CVE-2022-29829
https://notcve.org/view.php?id=CVE-2022-29829
24 Nov 2022 — Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.090U, GT Designer3 Version1 (GOT2000) versions from 1.122C to 1.290C and Motion Control Setting(GX Works3 related software) versions from 1.035M to 1.042U allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated users may view programs and project files or execute programs illegally. Uso de vulnerabilidad de clave criptográfica codificada en Mitsubishi ... • https://jvn.jp/vu/JVNVU97244961/index.html • CWE-321: Use of Hard-coded Cryptographic Key CWE-798: Use of Hard-coded Credentials •

CVE-2022-29828
https://notcve.org/view.php?id=CVE-2022-29828
24 Nov 2022 — Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated attackers may view programs and project file or execute programs illegally. El uso de una vulnerabilidad de clave criptográfica codificada en las versiones 1.000A y posteriores de Mitsubishi Electric GX Works3 permite que un atacante remoto no autenticado revele información sensible. Como res... • https://jvn.jp/vu/JVNVU97244961/index.html • CWE-321: Use of Hard-coded Cryptographic Key CWE-798: Use of Hard-coded Credentials •

CVE-2022-29827
https://notcve.org/view.php?id=CVE-2022-29827
24 Nov 2022 — Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated attackers may view programs and project files or execute programs illegally. El uso de una vulnerabilidad de clave criptográfica codificada en las versiones 1.000A y posteriores de Mitsubishi Electric GX Works3 permite que un atacante remoto no autenticado revele información sensible. Como re... • https://jvn.jp/vu/JVNVU97244961/index.html • CWE-321: Use of Hard-coded Cryptographic Key CWE-798: Use of Hard-coded Credentials •

CVE-2022-29826
https://notcve.org/view.php?id=CVE-2022-29826
24 Nov 2022 — Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.087R and Motion Control Setting(GX Works3 related software) versions from 1.000A to 1.042U allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated users may view programs and project files or execute programs illegally. Vulnerabilidad de almacenamiento de texto sin cifrar de información sensible en las versiones de Mitsubishi Electric GX Works3 ... • https://jvn.jp/vu/JVNVU97244961/index.html • CWE-312: Cleartext Storage of Sensitive Information •

CVE-2022-29825
https://notcve.org/view.php?id=CVE-2022-29825
24 Nov 2022 — Use of Hard-coded Password vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.090U and GT Designer3 Version1 (GOT2000) versions from 1.122C to 1.290C allows an unauthenticated attacker to disclose sensitive information. As a result, unauthenticated users may view programs and project files or execute programs illegally. El uso de la vulnerabilidad de contraseña codificada en las versiones Mitsubishi Electric GX Works3 de 1.000A a 1.090U y GT Designer3 Versión1 (GOT2000) de 1.122C a 1.2... • https://jvn.jp/vu/JVNVU97244961/index.html • CWE-259: Use of Hard-coded Password CWE-798: Use of Hard-coded Credentials •

CVE-2022-25164
https://notcve.org/view.php?id=CVE-2022-25164
24 Nov 2022 — Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z and Mitsubishi Electric MX OPC UA Module Configurator-R versions 1.08J and prior allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated attackers can gain unauthorized access to the MELSEC CPU module and the MELSEC OPC UA server module. Vulnerabilidad de almacenamiento de texto sin cifrar de información confidencial en Mitsubishi Electric ... • https://jvn.jp/vu/JVNVU97244961/index.html • CWE-312: Cleartext Storage of Sensitive Information •

CVE-2020-14496 – Mitsubishi Electric Multiple Factory Automation Engineering Software Products (Update A) - Permission Issues
https://notcve.org/view.php?id=CVE-2020-14496
19 May 2022 — Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed, tampered with, and/or destroyed. Una explotación con éxito de esta vulnerabilidad para múltiples Productos Mitsubishi Electric Factory Automation Engineering Software de varias versiones podría perm... • https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-02 • CWE-275: Permission Issues •

CVE-2020-14523 – Mitsubishi Electric Factory Automation Products Path Traversal
https://notcve.org/view.php?id=CVE-2020-14523
11 Feb 2022 — Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code. diversos productos de Mitsubishi Electric Factory Automation presentan una vulnerabilidad que permite a un atacante ejecutar código arbitrario • https://jvn.jp/vu/JVNVU90224831 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2020-14521 – Mitsubishi Electric Factory Automation Engineering Products Unquoted Search Path or Element
https://notcve.org/view.php?id=CVE-2020-14521
11 Feb 2022 — Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition. diversos productos de software de ingeniería de Mitsubishi Electric Factory Automation presentan una vulnerabilidad de ejecución de código malicioso. Un atacante malicioso podría usar esta vulnerabilidad para obtener información, modificar información y... • https://www.cisa.gov/uscert/ics/advisories/icsa-20-212-04 • CWE-276: Incorrect Default Permissions CWE-428: Unquoted Search Path or Element •

CVE-2021-20588
https://notcve.org/view.php?id=CVE-2021-20588
19 Feb 2021 — Improper handling of length parameter inconsistency vulnerability in Mitsubishi Electric FA Engineering Software(CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3 all versions, FR Configurator2 versions 1.24A and prior, GT Designer3 Version1(GOT1000) versions 1.250L and prior, GT Designer3 Version1(GOT2000) versions 1.250L and pr... • https://jvn.jp/vu/JVNVU92330101/index.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •