Vulnerabilities > Mitsubishielectric > GX Works2

DATE CVE VULNERABILITY TITLE RISK
2024-07-02 CVE-2024-22103 Out-of-bounds Write vulnerability in multiple products
Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).
local
low complexity
jungo mitsubishielectric CWE-787
5.5
2024-07-02 CVE-2024-22104 Out-of-bounds Write vulnerability in multiple products
Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).
local
low complexity
jungo mitsubishielectric CWE-787
5.5
2024-01-30 CVE-2023-6942 Missing Authentication for Critical Function vulnerability in Mitsubishielectric products
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 and later, FR Configurator2 all versions, GT Designer3 Version1(GOT1000) all versions, GT Designer3 Version1(GOT2000) all versions, GX Works2 versions 1.11M and later, GX Works3 all versions, MELSOFT Navigator versions 1.04E and later, MT Works2 all versions, MX Component versions 4.00A and later and MX OPC Server DA/UA all versions allows a remote unauthenticated attacker to bypass authentication by sending specially crafted packets and connect to the products illegally.
network
low complexity
mitsubishielectric CWE-306
7.5
2024-01-30 CVE-2023-6943 Unsafe Reflection vulnerability in Mitsubishielectric products
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 and later, FR Configurator2 all versions, GT Designer3 Version1(GOT1000) all versions, GT Designer3 Version1(GOT2000) all versions, GX Works2 versions 1.11M and later, GX Works3 all versions, MELSOFT Navigator versions 1.04E and later, MT Works2 all versions, MX Component versions 4.00A and later and MX OPC Server DA/UA all versions allows a remote unauthenticated attacker to execute a malicious code by RPC with a path to a malicious library while connected to the products.
network
low complexity
mitsubishielectric CWE-470
critical
9.8
2023-11-30 CVE-2023-5274 Improper Input Validation vulnerability in Mitsubishielectric GX Works2
Improper Input Validation vulnerability in simulation function of GX Works2 allows an attacker to cause a denial-of-service (DoS) condition on the function by sending specially crafted packets.
local
high complexity
mitsubishielectric CWE-20
4.7
2023-11-30 CVE-2023-5275 Improper Input Validation vulnerability in Mitsubishielectric GX Works2
Improper Input Validation vulnerability in simulation function of GX Works2 allows an attacker to cause a denial-of-service (DoS) condition on the function by sending specially crafted packets.
local
high complexity
mitsubishielectric CWE-20
4.7
2022-05-19 CVE-2020-14496 Unspecified vulnerability in Mitsubishielectric products
Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed, tampered with, and/or destroyed.
network
low complexity
mitsubishielectric
7.5
2022-02-11 CVE-2020-14521 Incorrect Default Permissions vulnerability in Mitsubishielectric products
Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability.
network
low complexity
mitsubishielectric CWE-276
critical
9.8
2022-02-11 CVE-2020-14523 Path Traversal vulnerability in Mitsubishielectric products
Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.
network
low complexity
mitsubishielectric CWE-22
7.5
2021-12-17 CVE-2021-20606 Out-of-bounds Read vulnerability in Mitsubishielectric Ezsocket, GX Works2 and Melsoft Navigator
Out-of-bounds Read vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior, Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior and Mitsubishi Electric EZSocket versions 5.4 and prior allows an attacker to cause a DoS condition in the software by getting a user to open malicious project file specially crafted by an attacker.
local
low complexity
mitsubishielectric CWE-125
5.5