← Back

CVE-2022-25164

nvd nist
Published: Nov 25, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z and Mitsubishi Electric MX OPC UA Module Configurator-R versions 1.08J and prior allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated attackers can gain unauthorized access to the MELSEC CPU module and the MELSEC OPC UA server module.

Affected (4)

Gx Works3
Mx Opc Ua Module Configurator R
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
From 1.000a to 1.011m
From 1.015r to 1.086q
From 1.087r
All versions

References (6)

Source: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Third Party AdvisoryVDB Entry
Source: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Source: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory

Timeline

No history available yet.