Brief

Summary:

A report issued by CISA (Cybersecurity and Infrastructure Security Agency) reveals a critical vulnerability in Mitsubishi Electric's FA Engineering Software Products, assigned a CVSS v3 score of 9.8. The vulnerabilities, missing authentication for critical function and unsafe reflection, allow an attacker to remotely exploit the products, potentially leading to unauthorized access, information disclosure, tampering, destruction, or deletion. The affected products include EZSocket, FR Configurator2, GT Designer3, GX Works2, MELSOFT Navigator, MT Works2, MX Component, and MX OPC Server DA/UA.

Mitigation measures recommended by Mitsubishi Electric include using firewalls, VPNs, and restricting physical access to computers and networks. CISA advises organizations to perform proper impact analysis and risk assessment before deploying defensive measures and encourages implementing recommended cybersecurity strategies for proactive defense.

No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 9.8 ATTENTION: Exploitable remotely/low attack complexity Vendor: Mitsubishi Electric Equipment: EZSocket, FR Configurator2, GT Designer3 Version1(GOT1000), GT Designer3 Version1(GOT2000), GX Works2, GX Works3, MELSOFT Navigator, MT Works2, MX Component, MX OPC Server DA/UA (Software packaged with MC Works64) Vulnerabilities: Missing Authentication for Critical Function, Unsafe Reflection 2. RISK

This content is restricted.

Highlights content goes here...

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 9.8 ATTENTION: Exploitable remotely/low attack complexity Vendor: Mitsubishi Electric Equipment: EZSocket, FR Configurator2, GT Designer3 Version1(GOT1000), GT Designer3 Version1(GOT2000), GX Works2, GX Works3, MELSOFT Navigator, MT Works2, MX Component, MX OPC Server DA/UA (Software packaged with MC Works64) Vulnerabilities: Missing Authentication for Critical Function, Unsafe Reflection 2. RISK

This content is restricted.

Cybersecurity and Infrastructure Security Agency

Quick Insight
RADA.AI
RADA.AI
Hello! I'm RADA.AI - Regulatory Analysis and Decision Assistance. Your Intelligent guide for compliance and decision-making. How can i assist you today?
Suggested

Form successfully submitted. One of our GRI rep will contact you shortly

Thanking You!

Enter your Email

Enter your registered username/email id.

Enter your Email

Enter your email id below to signup.
Individual Plan
$125 / month OR $1250 / year
Features
Best for: Researchers, Legal professionals, Academics
Enterprise Plan
Contact for Pricing
Features
Best for: Law Firms, Corporations, Government Bodies