CVE-2023-51776

Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jungo:windriver:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:mitsubishielectric:cpu_module_logging_configuration_tool:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:cw_configurator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:data_transfer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:data_transfer_classic:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:ezsocket:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:fr_configurator_sw3:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:fr_configurator2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:genesis64:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gt_got1000:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gt_got2000:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gt_softgot1000:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gt_softgot2000:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_developer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_logviewer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_works2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_works3:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:iq_works:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mi_configurator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mr_configurator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mr_configurator2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mx_component:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mx_opc_server_da\/ua:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:numerical_control_device_communication:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:px_developer\/monitor_tool:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:rt_toolbox3:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:rt_visualbox:*:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:mitsubishielectric:mrzjw3-mc2-utl_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:mrzjw3-mc2-utl:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:mitsubishielectric:sw0dnc-mneth-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:sw0dnc-mneth-b:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:mitsubishielectric:sw1dnc-ccbd2-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:sw1dnc-ccbd2-b:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:mitsubishielectric:sw1dnc-ccief-j_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:sw1dnc-ccief-j:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:mitsubishielectric:sw1dnc-ccief-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:sw1dnc-ccief-b:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:mitsubishielectric:sw1dnc-mnetg-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:sw1dnc-mnetg-b:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:mitsubishielectric:sw1dnc-qsccf-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:sw1dnc-qsccf-b:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:mitsubishielectric:sw1dnd-emsdk-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:sw1dnd-emsdk-b:-:*:*:*:*:*:*:*

History

13 Mar 2025, 20:15

Type Values Removed Values Added
CWE CWE-269

21 Nov 2024, 08:38

Type Values Removed Values Added
References () https://jungo.com/windriver/versions/ - Release Notes () https://jungo.com/windriver/versions/ - Release Notes
References () https://www.cisa.gov/news-events/ics-advisories/icsa-24-135-04 - Third Party Advisory, US Government Resource () https://www.cisa.gov/news-events/ics-advisories/icsa-24-135-04 - Third Party Advisory, US Government Resource
References () https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-001_en.pdf - Third Party Advisory () https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-001_en.pdf - Third Party Advisory

05 Jul 2024, 15:56

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
First Time Mitsubishielectric gt Softgot1000
Mitsubishielectric mrzjw3-mc2-utl
Jungo windriver
Mitsubishielectric fr Configurator Sw3
Mitsubishielectric sw0dnc-mneth-b Firmware
Mitsubishielectric gx Developer
Mitsubishielectric sw1dnc-ccief-b
Mitsubishielectric sw1dnc-ccief-b Firmware
Mitsubishielectric gx Logviewer
Mitsubishielectric mrzjw3-mc2-utl Firmware
Mitsubishielectric sw1dnc-qsccf-b Firmware
Mitsubishielectric data Transfer Classic
Mitsubishielectric sw1dnc-ccief-j Firmware
Mitsubishielectric genesis64
Mitsubishielectric sw1dnc-mnetg-b Firmware
Mitsubishielectric px Developer\/monitor Tool
Mitsubishielectric cw Configurator
Mitsubishielectric mx Opc Server Da\/ua
Mitsubishielectric mr Configurator
Mitsubishielectric fr Configurator2
Mitsubishielectric mx Component
Mitsubishielectric gt Got2000
Mitsubishielectric iq Works
Mitsubishielectric gx Works3
Mitsubishielectric numerical Control Device Communication
Mitsubishielectric sw1dnc-qsccf-b
Mitsubishielectric data Transfer
Mitsubishielectric gx Works2
Mitsubishielectric mi Configurator
Mitsubishielectric cpu Module Logging Configuration Tool
Mitsubishielectric sw0dnc-mneth-b
Mitsubishielectric sw1dnc-ccbd2-b Firmware
Mitsubishielectric sw1dnc-ccief-j
Mitsubishielectric sw1dnd-emsdk-b
Mitsubishielectric rt Toolbox3
Mitsubishielectric sw1dnc-ccbd2-b
Mitsubishielectric
Mitsubishielectric gt Got1000
Mitsubishielectric gt Softgot2000
Jungo
Mitsubishielectric mr Configurator2
Mitsubishielectric ezsocket
Mitsubishielectric rt Visualbox
Mitsubishielectric sw1dnd-emsdk-b Firmware
Mitsubishielectric sw1dnc-mnetg-b
Summary
  • (es) La gestión inadecuada de privilegios en Jungo WinDriver anterior a 12.1.0 permite a atacantes locales escalar privilegios y ejecutar código arbitrario.
References () https://jungo.com/windriver/versions/ - () https://jungo.com/windriver/versions/ - Release Notes
References () https://www.cisa.gov/news-events/ics-advisories/icsa-24-135-04 - () https://www.cisa.gov/news-events/ics-advisories/icsa-24-135-04 - Third Party Advisory, US Government Resource
References () https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-001_en.pdf - () https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-001_en.pdf - Third Party Advisory
CPE cpe:2.3:a:mitsubishielectric:data_transfer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mi_configurator:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:sw1dnc-ccbd2-b:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:ezsocket:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gt_softgot1000:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_developer:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:sw1dnc-ccief-j_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:mrzjw3-mc2-utl_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:sw1dnc-qsccf-b:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mx_component:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_logviewer:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_works2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:numerical_control_device_communication:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_works3:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:iq_works:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:fr_configurator_sw3:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:sw1dnc-ccief-b:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:rt_visualbox:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:fr_configurator2:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:mrzjw3-mc2-utl:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:sw0dnc-mneth-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mr_configurator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gt_got1000:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:cw_configurator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gt_softgot2000:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:px_developer\/monitor_tool:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:sw1dnc-mnetg-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:sw0dnc-mneth-b:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:cpu_module_logging_configuration_tool:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:sw1dnc-qsccf-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:data_transfer_classic:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:genesis64:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:sw1dnc-ccbd2-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gt_got2000:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:sw1dnc-ccief-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:sw1dnc-mnetg-b:-:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:rt_toolbox3:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:sw1dnc-ccief-j:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishielectric:sw1dnd-emsdk-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishielectric:sw1dnd-emsdk-b:-:*:*:*:*:*:*:*
cpe:2.3:a:jungo:windriver:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mr_configurator2:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mx_opc_server_da\/ua:*:*:*:*:*:*:*:*

02 Jul 2024, 16:15

Type Values Removed Values Added
Summary (en) Improper privilege management in Jungo WinDriver 12.1.0 allows local attackers to escalate privileges and execute arbitrary code. (en) Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code.

02 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-02 15:15

Updated : 2025-03-13 20:15


NVD link : CVE-2023-51776

Mitre link : CVE-2023-51776

CVE.ORG link : CVE-2023-51776


JSON object : View

Products Affected

mitsubishielectric

  • gt_got2000
  • mx_component
  • rt_visualbox
  • sw1dnc-qsccf-b_firmware
  • mrzjw3-mc2-utl
  • cw_configurator
  • genesis64
  • sw0dnc-mneth-b
  • mr_configurator2
  • sw1dnc-ccief-j_firmware
  • sw1dnc-qsccf-b
  • gx_works3
  • mx_opc_server_da\/ua
  • cpu_module_logging_configuration_tool
  • sw1dnc-ccief-j
  • sw1dnc-mnetg-b
  • sw1dnc-ccief-b
  • ezsocket
  • px_developer\/monitor_tool
  • gt_softgot1000
  • rt_toolbox3
  • gx_developer
  • sw0dnc-mneth-b_firmware
  • gt_softgot2000
  • data_transfer_classic
  • sw1dnc-ccbd2-b
  • mi_configurator
  • sw1dnd-emsdk-b_firmware
  • gx_works2
  • data_transfer
  • sw1dnc-ccbd2-b_firmware
  • sw1dnd-emsdk-b
  • iq_works
  • gt_got1000
  • numerical_control_device_communication
  • fr_configurator_sw3
  • fr_configurator2
  • sw1dnc-ccief-b_firmware
  • mr_configurator
  • mrzjw3-mc2-utl_firmware
  • sw1dnc-mnetg-b_firmware
  • gx_logviewer

jungo

  • windriver
CWE
NVD-CWE-noinfo CWE-269

Improper Privilege Management