CVE-2023-6943
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versions 1.325P and prior, GT Designer3 Version1(GOT2000) versions 1.320J and prior, GX Works2 versions 1.11M to 1.626C, GX Works3 versions 1.106L and prior, MELSOFT Navigator versions 1.04E to 2.102G, MT Works2 versions 1.190Y and prior, MX Component versions 4.00A to 5.007H and MX OPC Server DA/UA all versions allows a remote unauthenticated attacker to execute a malicious code by RPC with a path to a malicious library while connected to the products.
Published:Jan 30, 2024
Last Modified:Sep 19, 2025
EPS:Jan 30, 2024
EPSS Score:0.0397
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Mitsubishielectric
Product
Ezsocket
Mitsubishielectric
Ezsocket
Vendor
Mitsubishielectric
Product
Fr Configurator2
Mitsubishielectric
Fr Configurator2
Vendor
Mitsubishielectric
Product
Got1000
Mitsubishielectric
Got1000
Vendor
Mitsubishielectric
Product
Got2000
Mitsubishielectric
Got2000
Vendor
Mitsubishielectric
Product
Gx Works2
Mitsubishielectric
Gx Works2
Vendor
Mitsubishielectric
Product
Gx Works3
Mitsubishielectric
Gx Works3
Vendor
Mitsubishielectric
Product
Mc Works64
Mitsubishielectric
Mc Works64
Vendor
Mitsubishielectric
Product
Melsoft Navigator
Mitsubishielectric
Melsoft Navigator
Vendor
Mitsubishielectric
Product
Mt Works2
Mitsubishielectric
Mt Works2
Vendor
Mitsubishielectric
Product
Mx Component
Mitsubishielectric
Mx Component
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
