ICSA-25-338-01
·
Published 2025-12-04
·
View on CISA ICS-CERT ↗
Mitsubishi Electric GX Works2
CVSS 5.5
MEDIUM
Risk Summary
Successful exploitation of this vulnerability could open project files protected by user authentication using disclosed credential information, and obtain or modify project information.
CVEs (1)
Remediations
- The fixed version for this vulnerability is currently under development by Mitsubishi Electric. Until the fixed version is released, please implement the following mitigations:
- Use the PCs with the affected product installed in the LAN and block remote logins from untrusted networks, hosts, or users.
- Block unauthorized access by using a firewall or a virtual private network (VPN), etc., and allow remote logins only for trusted users when connecting the PCs with the affected product installed to the Internet.
- Restrict physical access to the PCs with the affected product installed, as well as to PCs and network devices that can communicate with those PCs.
- Install an antivirus software on the PCs running the affected product.
- Encrypt project files when sending or receiving them over the Internet.
- See Mitsubishi Electric's security bulletin for information on the availability of the security updates.
Affected Vendors
Mitsubishi Electric
Affected Products (1)
Mitsubishi Electric
·
GX Works2
vers:all/*
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more