Mitsubishi Electric FA Engineering Software (Update A)
Improper file permissions in Mitsubishi Electric FA Engineering software installation directories allow a local attacker to execute arbitrary code and modify system files. The vulnerability stems from incorrect access control on installation directories and allows an attacker with user-level access to inject code that executes with elevated privileges when other users run the affected tools. This affects 25 different engineering tools including PLC programmers, HMI designers, and device configuration utilities. Successful exploitation could result in unauthorized modification or deletion of PLC program files, safety configurations, and operational data, or denial of service to the engineering environment.
- Local access to the engineering workstation
- User privileges (no administrative access required)
- The affected software installed in a non-default location or with non-default permissions
Patching may require device reboot — plan for process interruption
/api/v1/advisories/4c97c1d6-4d9f-48e0-a628-3548d31a88f8