PT-2022-6046 · Mitsubishi · Mitsubishi Electric Mx Opc Ua Module Configurator-R+3
Anton Dorfman
+3
·
Published
2022-11-24
·
Updated
2023-06-29
·
CVE-2022-25164
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mitsubishi Electric GX Works3 versions 1.000A through 1.095Z
Mitsubishi Electric MX OPC UA Module Configurator-R versions 1.08J and prior
Description
The issue is related to the storage of sensitive information in cleartext, allowing a remote unauthenticated attacker to disclose this information. As a result, attackers can gain unauthorized access to the MELSEC CPU module and the MELSEC OPC UA server module.
Recommendations
For Mitsubishi Electric GX Works3 versions 1.000A through 1.095Z, update to a version that fixes the cleartext storage of sensitive information issue.
For Mitsubishi Electric MX OPC UA Module Configurator-R versions 1.08J and prior, update to a version that fixes the cleartext storage of sensitive information issue.
As a temporary workaround, consider restricting access to the MELSEC CPU module and the MELSEC OPC UA server module to minimize the risk of exploitation.
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Melsec Cpu Module
Melsec Opc Ua Server Module
Mitsubishi Electric Gx Works3
Mitsubishi Electric Mx Opc Ua Module Configurator-R