PT-2022-6046 · Mitsubishi · Mitsubishi Electric Mx Opc Ua Module Configurator-R+3

Anton Dorfman

+3

·

Published

2022-11-24

·

Updated

2023-06-29

·

CVE-2022-25164

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mitsubishi Electric GX Works3 versions 1.000A through 1.095Z Mitsubishi Electric MX OPC UA Module Configurator-R versions 1.08J and prior
Description The issue is related to the storage of sensitive information in cleartext, allowing a remote unauthenticated attacker to disclose this information. As a result, attackers can gain unauthorized access to the MELSEC CPU module and the MELSEC OPC UA server module.
Recommendations For Mitsubishi Electric GX Works3 versions 1.000A through 1.095Z, update to a version that fixes the cleartext storage of sensitive information issue. For Mitsubishi Electric MX OPC UA Module Configurator-R versions 1.08J and prior, update to a version that fixes the cleartext storage of sensitive information issue. As a temporary workaround, consider restricting access to the MELSEC CPU module and the MELSEC OPC UA server module to minimize the risk of exploitation.

Fix

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2022-07510
CVE-2022-25164

Affected Products

Melsec Cpu Module
Melsec Opc Ua Server Module
Mitsubishi Electric Gx Works3
Mitsubishi Electric Mx Opc Ua Module Configurator-R