CVE-2023-5247

Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software Products allows a malicious attacker to execute a malicious code by having legitimate users open a specially crafted project file, which could result in information disclosure, tampering and deletion, or a denial-of-service (DoS) condition.
References
Link Resource
https://jvn.jp/vu/JVNVU93383160/ Mitigation Third Party Advisory
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-016_en.pdf Mitigation Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mitsubishielectric:gx_works3:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_iq_appportal:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_navigator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:motion_control_setting:*:*:*:*:*:*:*:*

History

05 Dec 2023, 18:28

Type Values Removed Values Added
CWE CWE-610
First Time Mitsubishielectric melsoft Iq Appportal
Mitsubishielectric motion Control Setting
Mitsubishielectric gx Works3
Mitsubishielectric melsoft Navigator
Mitsubishielectric
CPE cpe:2.3:a:mitsubishielectric:melsoft_navigator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:gx_works3:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:motion_control_setting:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_iq_appportal:*:*:*:*:*:*:*:*
References () https://jvn.jp/vu/JVNVU93383160/ - () https://jvn.jp/vu/JVNVU93383160/ - Mitigation, Third Party Advisory
References () https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-016_en.pdf - () https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-016_en.pdf - Mitigation, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

30 Nov 2023, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-30 04:15

Updated : 2023-12-10 15:26


NVD link : CVE-2023-5247

Mitre link : CVE-2023-5247

CVE.ORG link : CVE-2023-5247


JSON object : View

Products Affected

mitsubishielectric

  • motion_control_setting
  • gx_works3
  • melsoft_iq_appportal
  • melsoft_navigator
CWE
CWE-610

Externally Controlled Reference to a Resource in Another Sphere

CWE-73

External Control of File Name or Path