Vulnerabilidades em Mitsubishi Electric Corporation

127 resultados
Análise Vexday

Com 125 CVEs catalogadas, o portfólio de vulnerabilidades da Mitsubishi Electric Corporation apresenta taxa de exploração ativa abaixo da média geral do catálogo CISA KEV, sem nenhum registro confirmado de exploração em ambiente real. Ainda assim, 18 vulnerabilidades de severidade crítica merecem atenção, especialmente considerando que o tipo de falha mais frequente é CWE-306 — ausência de autenticação para função crítica —, padrão que historicamente representa risco elevado em ambientes de tecnologia operacional e sistemas de controle industrial. A CVE mais perigosa atualmente monitorada, CVE-2020-5666, registra EPSS de 0,084, indicando probabilidade de exploração ainda moderada, mas seu contexto de origem reforça a necessidade de rastreamento contínuo. A ausência de PoCs públicas reduz a superfície de ameaça imediata, porém as 5 CVEs surgidas nos últimos 90 dias sinalizam que o ritmo de descoberta de novas falhas permanece ativo e deve ser acompanhado de perto por equipes de segurança em ambientes críticos.

CVE-2023-2846HIGHAuthentication Bypass Vulnerability in MELSEC-F Series main moduleEPSS 1.3%CVE-2020-5594Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows cleartext transmissiEPSS 1.3%CVE-2022-29831HIGHUse of Hard-coded Password vulnerability in Mitsubishi Electric Corporation GX Works3 versions from 1.015R to 1.095Z allows a remote unautheEPSS 1.3%CVE-2022-29830CRITICALUse of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z, and Motion Control SettinEPSS 1.2%CVE-2022-40267MEDIUMAuthentication Bypass Vulnerability in Web Server Function on MELSEC SeriesEPSS 1.2%CVE-2023-0457HIGHInformation Disclosure Vulnerability in MELSEC SeriesEPSS 1.2%CVE-2022-33323HIGHAuthentication Bypass Vulnerability in Robot Controller of MELFA SD/SQ series and F-seriesEPSS 1.1%CVE-2023-1618HIGHAuthentication Bypass Vulnerability in MELSEC WS Series Ethernet Interface ModuleEPSS 1.1%CVE-2025-3699CRITICALMissing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 all versions, G-50-W all versions, G-50A EPSS 1.1%CVE-2024-1916CRITICALInteger Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remEPSS 1.1%CVE-2024-1917CRITICALInteger Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remEPSS 1.1%CVE-2024-0802CRITICALIncorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote uEPSS 1.1%CVE-2020-5657Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in TCP/IP function included in the firmwareEPSS 1.1%CVE-2022-29827MEDIUMUse of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows a remote unauthentiEPSS 1.1%CVE-2022-29828MEDIUMUse of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows a remote unauthentiEPSS 1.1%CVE-2022-29829MEDIUMUse of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.090U, GT Designer3 Version1 (GOEPSS 1.1%CVE-2024-1915CRITICALIncorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote uEPSS 1.0%CVE-2024-0803CRITICALInteger Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remEPSS 1.0%CVE-2020-5665Improper check or handling of exceptional conditions in MELSEC iQ-F series FX5U(C) CPU unit firmware version 1.060 and earlier allows an attEPSS 1.0%CVE-2025-8531MEDIUMImproper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series Q03UDVCPU, Q04UDVCPU, QEPSS 1.0%