Mitsubishi Electric FA Engineering Software Products (Update D)
Multiple Mitsubishi Electric FA engineering software products contain vulnerabilities in authentication and data handling. Affected products include EZSocket (versions 3.0 to 5.92), GT Designer3 for GOT1000 and GOT2000, GX Works2, GX Works3, MELSOFT Navigator, MT Works2, MX Component, and MX OPC Server DA/UA. These products are used to develop, program, and configure industrial control devices such as PLCs and HMIs. An attacker with network access can exploit these vulnerabilities to disclose, modify, or delete project files and configurations, or to cause the software to stop responding. The vulnerabilities do not require authentication and have a straightforward attack vector.
- Network access to the engineering workstation running one of the affected Mitsubishi products (port and protocol depend on the specific product)
- No authentication required for exploitation
- The affected product must be installed and running on the target workstation
Patching may require device reboot — plan for process interruption
/api/v1/advisories/f0cda3bd-8380-4ee3-9a85-10082e5b7595