Vulnerabilities > Mitsubishielectric > GX Works2 > High

DATE CVE VULNERABILITY TITLE RISK
2024-07-02 CVE-2024-22106 Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute arbitrary code, or cause a Denial of Service (DoS).
local
low complexity
jungo mitsubishielectric
7.8
2024-07-02 CVE-2024-25086 Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code.
local
low complexity
jungo mitsubishielectric
7.8
2024-07-02 CVE-2024-25088 Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code.
local
low complexity
jungo mitsubishielectric
7.8
2024-07-02 CVE-2024-26314 Improper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and execute arbitrary code.
local
low complexity
jungo mitsubishielectric
7.8
2024-07-02 CVE-2023-51776 Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code.
local
low complexity
jungo mitsubishielectric
7.8
2024-01-30 CVE-2023-6942 Unspecified vulnerability in Mitsubishielectric products
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) all versions, GT Designer3 Version1(GOT2000) versions 1.320J and prior, GX Works2 versions 1.11M and later, GX Works3 versions 1.106L and prior, MELSOFT Navigator versions 1.04E to 2.102G, MT Works2 versions 1.190Y and prior, MX Component versions 4.00A to 5.007H and MX OPC Server DA/UA all versions allows a remote unauthenticated attacker to bypass authentication by sending specially crafted packets and connect to the products illegally.
network
low complexity
mitsubishielectric
7.5
2021-12-17 CVE-2021-20608 Unspecified vulnerability in Mitsubishielectric GX Works2
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior allows a remote unauthenticated attacker to cause a DoS condition in GX Works2 by getting GX Works2 to read a tampered program file from a Mitsubishi Electric PLC by sending malicious crafted packets to tamper with the program file.
network
low complexity
mitsubishielectric
7.5
2020-06-30 CVE-2020-5603 Resource Exhaustion vulnerability in Mitsubishielectric products
Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver.
network
low complexity
mitsubishielectric CWE-400
7.5
2020-06-30 CVE-2020-5602 XXE vulnerability in Mitsubishielectric products
Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver.
network
low complexity
mitsubishielectric CWE-611
7.5