CVE-2023-5247
30.11.2023, 04:15
Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software Products allows a malicious attacker to execute a malicious code by having legitimate users open a specially crafted project file, which could result in information disclosure, tampering and deletion, or a denial-of-service (DoS) condition.Enginsight
Vendor | Product | Version |
---|---|---|
mitsubishielectric | gx_works3 | * |
mitsubishielectric | melsoft_iq_appportal | * |
mitsubishielectric | melsoft_navigator | * |
mitsubishielectric | motion_control_setting | * |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-73 - External Control of File Name or PathThe software allows user input to control or influence paths or file names that are used in filesystem operations.
- CWE-610 - Externally Controlled Reference to a Resource in Another SphereThe product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.