TROYANOSYVIRUS
Volver a CVEs

CVE-2023-6943

CRITICAL
9.8

Descripcion

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versions 1.325P and prior, GT Designer3 Version1(GOT2000) versions 1.320J and prior, GX Works2 versions 1.11M to 1.626C, GX Works3 versions 1.106L and prior, MELSOFT Navigator versions 1.04E to 2.102G, MT Works2 versions 1.190Y and prior, MX Component versions 4.00A to 5.007H and MX OPC Server DA/UA all versions allows a remote unauthenticated attacker to execute a malicious code by RPC with a path to a malicious library while connected to the products.

Detalles CVE

Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado1/30/2024
Ultima modificacion9/19/2025
Fuentenvd
Avistamientos honeypot0

Productos afectados

mitsubishielectric:ezsocketmitsubishielectric:fr_configurator2mitsubishielectric:got1000mitsubishielectric:got2000mitsubishielectric:gx_works2mitsubishielectric:gx_works3mitsubishielectric:mc_works64mitsubishielectric:melsoft_navigatormitsubishielectric:mt_works2mitsubishielectric:mx_component

Debilidades (CWE)

CWE-470

Referencias

https://jvn.jp/vu/JVNVU95103362(Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp)
https://www.cisa.gov/news-events/ics-advisories/icsa-24-030-02(Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp)
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-020_en.pdf(Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp)
https://jvn.jp/vu/JVNVU95103362(af854a3a-2127-422b-91ae-364da2661108)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.