cbcvebase.
CVE-2023-4088
published 2023-09-20

CVE-2023-4088: Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products allows a malicious local attacker to…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products allows a malicious local attacker to execute a malicious code, resulting in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition, if the product is installed in a folder other than the default installation folder.

Affected

25 ranges
VendorProductVersion rangeFixed in
mitsubishi_electric_corporational-pcs_win-e
mitsubishi_electric_corporationcpu_module_logging_configuration_tool
mitsubishi_electric_corporationdata_transfer
mitsubishi_electric_corporationdata_transfer_classic
mitsubishi_electric_corporationezsocket
mitsubishi_electric_corporationfr_configurator2
mitsubishi_electric_corporationfx_configurator-en
mitsubishi_electric_corporationfx_configurator-en-l
mitsubishi_electric_corporationfx_configurator-fp
mitsubishi_electric_corporationgt_designer3_version1
mitsubishi_electric_corporationgt_softgot1000_version3
mitsubishi_electric_corporationgt_softgot2000_version1
mitsubishi_electric_corporationgx_logviewer
mitsubishi_electric_corporationgx_works2
mitsubishi_electric_corporationgx_works3
mitsubishi_electric_corporationmelsoft_fielddeviceconfigurator
mitsubishi_electric_corporationmelsoft_iq_appportal
mitsubishi_electric_corporationmelsoft_mailab
mitsubishi_electric_corporationmelsoft_navigator
mitsubishi_electric_corporationmelsoft_update_manager
mitsubishi_electric_corporationmx_component
mitsubishi_electric_corporationmx_sheet
mitsubishi_electric_corporationpx_developer
mitsubishi_electric_corporationrt_toolbox3
mitsubishi_electric_corporationrt_visualbox