CVE-2023-4088

Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products allows a malicious local attacker to execute a malicious code, resulting in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition, if the product is installed in a folder other than the default installation folder.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mitsubishielectric:gx_works3:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:34

Type Values Removed Values Added
References () https://jvn.jp/vu/JVNVU96447193/index.html - () https://jvn.jp/vu/JVNVU96447193/index.html -
References () https://www.cisa.gov/news-events/ics-advisories/icsa-23-269-03 - () https://www.cisa.gov/news-events/ics-advisories/icsa-23-269-03 -
References () https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-010_en.pdf - Vendor Advisory () https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-010_en.pdf - Vendor Advisory
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 9.3

04 Jul 2024, 10:15

Type Values Removed Values Added
Summary (en) Incorrect Default Permissions vulnerability due to incomplete fix to address CVE-2020-14496 in Mitsubishi Electric Corporation FA engineering software products allows a malicious local attacker to execute a malicious code, which could result in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition. However, if the mitigated version described in the advisory for CVE-2020-14496 is used and installed in the default installation folder, this vulnerability does not affect the products. (en) Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products allows a malicious local attacker to execute a malicious code, resulting in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition, if the product is installed in a folder other than the default installation folder.

28 Sep 2023, 00:15

Type Values Removed Values Added
References
  • (MISC) https://www.cisa.gov/news-events/ics-advisories/icsa-23-269-03 -
  • (MISC) https://jvn.jp/vu/JVNVU96447193/index.html -

25 Sep 2023, 16:28

Type Values Removed Values Added
CPE cpe:2.3:a:mitsubishielectric:gx_works3:*:*:*:*:*:*:*:*
First Time Mitsubishielectric gx Works3
Mitsubishielectric
References (MISC) https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-010_en.pdf - (MISC) https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-010_en.pdf - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-276

20 Sep 2023, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-20 03:15

Updated : 2024-11-21 08:34


NVD link : CVE-2023-4088

Mitre link : CVE-2023-4088

CVE.ORG link : CVE-2023-4088


JSON object : View

Products Affected

mitsubishielectric

  • gx_works3
CWE
CWE-276

Incorrect Default Permissions