CVE-2023-4088

Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products allows a malicious local attacker to execute a malicious code, resulting in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition, if the product is installed in a folder other than the default installation folder.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mitsubishielectric:gx_works3:*:*:*:*:*:*:*:*

History

04 Jul 2024, 10:15

Type Values Removed Values Added
Summary (en) Incorrect Default Permissions vulnerability due to incomplete fix to address CVE-2020-14496 in Mitsubishi Electric Corporation FA engineering software products allows a malicious local attacker to execute a malicious code, which could result in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition. However, if the mitigated version described in the advisory for CVE-2020-14496 is used and installed in the default installation folder, this vulnerability does not affect the products. (en) Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products allows a malicious local attacker to execute a malicious code, resulting in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition, if the product is installed in a folder other than the default installation folder.

28 Sep 2023, 00:15

Type Values Removed Values Added
References
  • (MISC) https://www.cisa.gov/news-events/ics-advisories/icsa-23-269-03 -
  • (MISC) https://jvn.jp/vu/JVNVU96447193/index.html -

25 Sep 2023, 16:28

Type Values Removed Values Added
CWE CWE-276
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References (MISC) https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-010_en.pdf - (MISC) https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-010_en.pdf - Vendor Advisory
CPE cpe:2.3:a:mitsubishielectric:gx_works3:*:*:*:*:*:*:*:*
First Time Mitsubishielectric
Mitsubishielectric gx Works3

20 Sep 2023, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-20 03:15

Updated : 2024-07-04 10:15


NVD link : CVE-2023-4088

Mitre link : CVE-2023-4088

CVE.ORG link : CVE-2023-4088


JSON object : View

Products Affected

mitsubishielectric

  • gx_works3
CWE
CWE-276

Incorrect Default Permissions