CVE Feed

    Dashboard / CVE / CVE-2022-25164

    CVE-2022-25164

    Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z and Mitsubishi Electric MX OPC UA Module Configurator-R versions 1.08J and prior allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated attackers can gain unauthorized access to the MELSEC CPU module and the MELSEC OPC UA server module.

    Published:Nov 24, 2022
    Last Modified:Apr 25, 2025
    EPS:Nov 24, 2022
    EPSS Score:0.00262
    CVSS Score:8.6

    Affected Products

    Vendor
    Mitsubishielectric
    Product
    Gx Works3
    Vendor
    Mitsubishielectric
    Product
    Mx Opc Ua Module Configurator-r

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High