Aller au contenu

Fiche vulnérabilité

CVE-2022-25164 : faille élevée mitsubishielectric gx works3 (CVSS 7.5)

Description

Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z and Mitsubishi Electric MX OPC UA Module Configurator-R versions 1.08J and prior allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated attackers can gain unauthorized access to the MELSEC CPU module and the MELSEC OPC UA server module.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
25 nov. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • mitsubishielectric gx works3
  • mitsubishielectric mx opc ua module configurator-r

Références

Rechercher une autre vulnérabilité dans la base CVE