← Back to home
ICSA-24-030-02  ·  Published 2025-09-18  ·  View on CISA ICS-CERT ↗

Mitsubishi Electric FA Engineering Software Products (Update D)

CVSS 9.8 CRITICAL

Risk Summary

Successful exploitation of these vulnerabilities could allow an attacker to disclose, tamper with, destroy or delete information in the products, or cause a denial-of-service (DoS) condition on the products.

Remediations

  • Mitsubishi Electric recommends users take the following mitigation measures to minimize the risk of exploiting these vulnerabilities:
  • EZSocket: Download version 5.A or later.
  • GT Designer3 Version1(GOT1000): Download version 1.330U or later.
  • GT Designer3 Version1(GOT2000): Download version 1.325P or later.
  • GX Works2: Download version 1.630G or later.
  • GX Works3: Download version 1.110Q or later.
  • MELSOFT Navigator: Download version 2.106L or later.
  • MT Works2: Download version 1.195D or later.
  • MX Component: Download version 5.008J or later.
  • When connecting your personal computer with the affected products to the internet, use a firewall, virtual private network (VPN), etc., to prevent unauthorized access and allow only trusted users to remote login.
  • Use your personal computer with the affected products within a LAN and block access from untrusted networks and hosts.
  • Restrict physical access to your computer using the affected products as well as to the personal computers and network devices that can communicate with it.
  • Install antivirus software on your personal computer using the affected products and on the personal computers that can communicate with it.
  • Don't open untrusted files or click untrusted links.
  • For more information, see Mitsubishi Electric's security advisory.

Affected Vendors

Mitsubishi Electric

Affected Products (9)

Mitsubishi Electric · EZSocket >=3.0|<5.92
Mitsubishi Electric · GT Designer3 Version1(GOT1000) <=1.325P
Mitsubishi Electric · GT Designer3 Version1(GOT2000) <=1.320J
Mitsubishi Electric · GX Works2 >=1.11M|<1.626C
Mitsubishi Electric · GX Works3 <=1.106L
Mitsubishi Electric · MELSOFT Navigator >=1.04E|<2.102G
Mitsubishi Electric · MT Works2 <=1.190Y
Mitsubishi Electric · MX Component >=4.00A|<5.007H
Mitsubishi Electric · MX OPC Server DA/UA (Software packaged with MC Works64) vers:all/*

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more