CVE-2023-5247

M

alicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software Products allows a malicious attacker to execute a malicious code by having legitimate users open a specially crafted project file, which could result in information disclosure, tampering and deletion, or a denial-of-service (DoS) condition.

References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mitsubishielectric:gx_works3:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_iq_appportal:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:melsoft_navigator:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:motion_control_setting:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:41

Type Values Removed Values Added
References () https://jvn.jp/vu/JVNVU93383160/ - Mitigation, Third Party Advisory () https://jvn.jp/vu/JVNVU93383160/ - Mitigation, Third Party Advisory
References () https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-016_en.pdf - Mitigation, Vendor Advisory () https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-016_en.pdf - Mitigation, Vendor Advisory

Information

Published : 2023-11-30 04:15

Updated : 2024-11-21 08:41


NVD link : CVE-2023-5247

Mitre link : CVE-2023-5247

CVE.ORG link : CVE-2023-5247


JSON object : View

CWE
CWE-73

External Control of File Name or Path

CWE-610

Externally Controlled Reference to a Resource in Another Sphere