TROYANOSYVIRUS
Back to CVEs

CVE-2023-6943

CRITICAL
9.8

Description

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versions 1.325P and prior, GT Designer3 Version1(GOT2000) versions 1.320J and prior, GX Works2 versions 1.11M to 1.626C, GX Works3 versions 1.106L and prior, MELSOFT Navigator versions 1.04E to 2.102G, MT Works2 versions 1.190Y and prior, MX Component versions 4.00A to 5.007H and MX OPC Server DA/UA all versions allows a remote unauthenticated attacker to execute a malicious code by RPC with a path to a malicious library while connected to the products.

CVE Details

CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published1/30/2024
Last Modified9/19/2025
Sourcenvd
Honeypot Sightings0

Affected Products

mitsubishielectric:ezsocketmitsubishielectric:fr_configurator2mitsubishielectric:got1000mitsubishielectric:got2000mitsubishielectric:gx_works2mitsubishielectric:gx_works3mitsubishielectric:mc_works64mitsubishielectric:melsoft_navigatormitsubishielectric:mt_works2mitsubishielectric:mx_component

Weaknesses (CWE)

CWE-470

References

https://jvn.jp/vu/JVNVU95103362(Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp)
https://www.cisa.gov/news-events/ics-advisories/icsa-24-030-02(Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp)
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-020_en.pdf(Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp)
https://jvn.jp/vu/JVNVU95103362(af854a3a-2127-422b-91ae-364da2661108)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.