Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-4088— Malicious Code Execution Vulnerability in FA Engineering Software Products

CVSS 9.3 · Critical EPSS 0.03% · P7
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-4088

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Malicious Code Execution Vulnerability in FA Engineering Software Products
Source: NVD (National Vulnerability Database)
Vulnerability Description
Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products allows a malicious local attacker to execute a malicious code, resulting in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition, if the product is installed in a folder other than the default installation folder.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
缺省权限不正确
Source: NVD (National Vulnerability Database)
Vulnerability Title
Mitsubishi Electric FA engineering software 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mitsubishi Electric FA engineering software是日本三菱电机(Mitsubishi Electric)公司的一个工程软件。提供提高设计和调试的效率,减少停机时间和保护数据。 Mitsubishi Electric FA engineering software 存在安全漏洞。攻击者利用该漏洞执行恶意代码,可能导致信息泄露、篡改和删除或拒绝。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Mitsubishi Electric CorporationGX Works3 all versions -
Mitsubishi Electric CorporationAL-PCS/WIN-E all versions -
Mitsubishi Electric CorporationCPU Module Logging Configuration Tool all versions -
Mitsubishi Electric CorporationEZSocket all versions -
Mitsubishi Electric CorporationFR Configurator2 all versions -
Mitsubishi Electric CorporationFX Configurator-EN all versions -
Mitsubishi Electric CorporationFX Configurator-EN-L all versions -
Mitsubishi Electric CorporationFX Configurator-FP all versions -
Mitsubishi Electric CorporationGT Designer3 Version1(GOT1000) all versions -
Mitsubishi Electric CorporationGT Designer3 Version1(GOT2000) all versions -
Mitsubishi Electric CorporationGT SoftGOT1000 Version3 all versions -
Mitsubishi Electric CorporationGT SoftGOT2000 Version1 all versions -
Mitsubishi Electric CorporationGX LogViewer all versions -
Mitsubishi Electric CorporationGX Works2 all versions -
Mitsubishi Electric CorporationMELSOFT FieldDeviceConfigurator all versions -
Mitsubishi Electric CorporationMELSOFT iQ AppPortal all versions -
Mitsubishi Electric CorporationMELSOFT MaiLab all versions -
Mitsubishi Electric CorporationMELSOFT Navigator all versions -
Mitsubishi Electric CorporationMELSOFT Update Manager all versions -
Mitsubishi Electric CorporationMX Component all versions -
Mitsubishi Electric CorporationMX Sheet all versions -
Mitsubishi Electric CorporationPX Developer all versions -
Mitsubishi Electric CorporationRT ToolBox3 all versions -
Mitsubishi Electric CorporationRT VisualBox all versions -
Mitsubishi Electric CorporationData Transfer all versions -
Mitsubishi Electric CorporationData Transfer Classic all versions -

II. Public POCs for CVE-2023-4088

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-4088

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2023-4088

No comments yet


Leave a comment