Mitsubishi Electric FA Engineering Software Products
Mitsubishi Electric FA engineering software products (GX Works3, MELSOFT Navigator, iQ AppPortal, Motion Control Setting) contain an unsafe file handling vulnerability (CWE-73) that allows malicious code execution when a user opens a specially crafted project file. All versions are affected. Successful exploitation could result in information disclosure (theft of proprietary control logic and designs), tampering (modification of process parameters or control logic), or denial-of-service (deletion of project files or workstation compromise). No vendor patch is available; Mitsubishi Electric recommends mitigation through user education, network isolation, and antivirus deployment.
- File opening by a user (social engineering or physical access required)
- User with permissions to run Mitsubishi FA engineering software
- Specially crafted project file in a format recognized by the affected software
Patching may require device reboot — plan for process interruption
/api/v1/advisories/f01b2a65-d566-472c-9034-8ec0d01bef95