Vulnerabilidades en Mitsubishi Electric Corporation

126 resultados
Análisis Vexday

Com 125 CVEs catalogadas, o portfólio de vulnerabilidades da Mitsubishi Electric Corporation apresenta taxa de exploração ativa abaixo da média geral do catálogo CISA KEV, sem nenhum registro confirmado de exploração em ambiente real. Ainda assim, 18 vulnerabilidades de severidade crítica merecem atenção, especialmente considerando que o tipo de falha mais frequente é CWE-306 — ausência de autenticação para função crítica —, padrão que historicamente representa risco elevado em ambientes de tecnologia operacional e sistemas de controle industrial. A CVE mais perigosa atualmente monitorada, CVE-2020-5666, registra EPSS de 0,084, indicando probabilidade de exploração ainda moderada, mas seu contexto de origem reforça a necessidade de rastreamento contínuo. A ausência de PoCs públicas reduz a superfície de ameaça imediata, porém as 5 CVEs surgidas nos últimos 90 dias sinalizam que o ritmo de descoberta de novas falhas permanece ativo e deve ser acompanhado de perto por equipes de segurança em ambientes críticos.

CVE-2024-8403HIGHDenial-of-Service Vulnerability in Ethernet port on MELSEC iQ-F Ethernet Module and EtherNet/IP ModuleEPSS 0.7%CVE-2026-8805HIGHDenial-of-service (DoS) vulnerability in MELSEC iQ-F Series EtherNet/IP moduleEPSS 0.6%CVE-2026-8806HIGHDenial-of-service (DoS) vulnerability in MELSEC iQ-F Series FX5-ENET/IP Ethernet moduleEPSS 0.6%CVE-2025-2399MEDIUMDenial of Service (DoS) Vulnerability in Mitsubishi Electric CNC SeriesEPSS 0.6%CVE-2022-29832LOWCleartext Storage of Sensitive Information in Memory vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later, GEPSS 0.6%CVE-2023-2063MEDIUMInformation disclosure, tampering, deletion and destruction vulnerability in MELSEC iQ-R Series / iQ-F Series EtherNet/IP ModulesEPSS 0.6%CVE-2024-1573MEDIUMMissing Authentication for Critical Function vulnerability in the mobile monitoring feature of Mitsubishi Electric GENESIS64 versions 10.97.EPSS 0.6%CVE-2025-5514MEDIUMDenial-of-Service(DoS) Vulnerability in Web server function on MELSEC iQ-F Series CPU moduleEPSS 0.6%CVE-2024-7316MEDIUMDenial of Service (DoS) Vulnerability in Mitsubishi Electric CNC SeriesEPSS 0.6%CVE-2023-2061MEDIUMAuthentication bypass vulnerability in MELSEC iQ-R Series / iQ-F Series EtherNet/IP ModulesEPSS 0.5%CVE-2025-15080HIGHInformation Disclosure, Information Tampering, and Denial of Service (DoS) Vulnerability in Mitsubishi Electric proprietary protocol communication and SLMP communication for FA productsEPSS 0.5%CVE-2025-5022MEDIUMWeak Password Requirements vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versionsEPSS 0.5%CVE-2025-11774HIGHMalicious Code Execution Vulnerability in the Software Keyboard Function of GENESIS64, ICONICS Suite, Mobile HMI, and MC Works64EPSS 0.5%CVE-2023-0525HIGHWeak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.49.000 and prior, GT25 modEPSS 0.5%CVE-2022-40268MEDIUMImproper Restriction of Rendered UI Layers or Frames vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.EPSS 0.5%CVE-2022-29825MEDIUMUse of Hard-coded Password vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.090U, GT Designer3 Version1 (GOT2000) veEPSS 0.5%CVE-2025-7405HIGHInformation Disclosure, Information Tampering, and Denial of Service (DoS) Vulnerability in MELSEC iQ-F Series CPU moduleEPSS 0.4%CVE-2026-1875HIGHDenial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series EtherNet/IP moduleEPSS 0.4%CVE-2026-1876HIGHDenial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series Ethernet moduleEPSS 0.4%CVE-2026-1874HIGHDenial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series EtherNet/IP module and Ethernet moduleEPSS 0.4%