PT-2022-5974 · Mitsubishi · Mitsubishi Electric Gx Works3+1
Published
2022-11-24
·
Updated
2025-11-07
·
CVE-2022-29830
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z
Motion Control Setting(GX Works3 related software) versions from 1.000A and later
Description
The issue is related to the use of a hard-coded cryptographic key, allowing a remote unauthenticated attacker to disclose or tamper with sensitive information. This could result in unauthenticated attackers obtaining information about project files illegally. The vulnerability may also allow an attacker to execute arbitrary code by replacing a project file.
Recommendations
For Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z, consider disabling the use of hard-coded cryptographic keys until a patch is available.
For Motion Control Setting(GX Works3 related software) versions from 1.000A and later, restrict access to sensitive project files to minimize the risk of exploitation.
As a temporary workaround, avoid using the affected software for sensitive projects until the issue is resolved.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mitsubishi Electric Gx Works3
Motion Control Setting