CVE-2022-29832
Published: Nov 24, 2022
Modified: Apr 25, 2025
CVSS v3.1
3.7
Description
Cleartext Storage of Sensitive Information in Memory vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later, GX Works2 all versions and GX Developer versions 8.40S and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated users could obtain information about the project file for MELSEC safety CPU modules or project file for MELSEC Q/FX/L series with security setting.
| Vendor | Product | Versions |
|---|---|---|
Mitsubishi Electric Corporation | GX Works3 | affected 1.015R and later |
Mitsubishi Electric Corporation | GX Works2 | affected all versions |
Mitsubishi Electric Corporation | GX Developer | affected 8.40S and later |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now