Vulnerabilities > Mitsubishielectric > FR Configurator2 > High

DATE CVE VULNERABILITY TITLE RISK
2024-07-02 CVE-2024-22106 Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute arbitrary code, or cause a Denial of Service (DoS).
local
low complexity
jungo mitsubishielectric
7.8
2024-07-02 CVE-2024-25086 Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code.
local
low complexity
jungo mitsubishielectric
7.8
2024-07-02 CVE-2024-25088 Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code.
local
low complexity
jungo mitsubishielectric
7.8
2024-07-02 CVE-2024-26314 Improper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and execute arbitrary code.
local
low complexity
jungo mitsubishielectric
7.8
2024-07-02 CVE-2023-51776 Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code.
local
low complexity
jungo mitsubishielectric
7.8
2024-01-30 CVE-2023-6942 Missing Authentication for Critical Function vulnerability in Mitsubishielectric products
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 and later, FR Configurator2 all versions, GT Designer3 Version1(GOT1000) all versions, GT Designer3 Version1(GOT2000) all versions, GX Works2 versions 1.11M and later, GX Works3 all versions, MELSOFT Navigator versions 1.04E and later, MT Works2 all versions, MX Component versions 4.00A and later and MX OPC Server DA/UA all versions allows a remote unauthenticated attacker to bypass authentication by sending specially crafted packets and connect to the products illegally.
network
low complexity
mitsubishielectric CWE-306
7.5
2022-05-19 CVE-2020-14496 Unspecified vulnerability in Mitsubishielectric products
Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed, tampered with, and/or destroyed.
network
low complexity
mitsubishielectric
7.5
2022-02-11 CVE-2020-14523 Path Traversal vulnerability in Mitsubishielectric products
Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.
network
low complexity
mitsubishielectric CWE-22
7.5