CVE-2023-5247: Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software...

7.8 CVSS

Description

Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software Products allows a malicious attacker to execute a malicious code by having legitimate users open a specially crafted project file, which could result in information disclosure, tampering and deletion, or a denial-of-service (DoS) condition.

Classification

CVE ID: CVE-2023-5247

CVSS Base Severity: HIGH

CVSS Base Score: 7.8

Affected Products

Vendor: Mitsubishi Electric Corporation

Product: GX Works3

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.07% (probability of being exploited)

EPSS Percentile: 30.92% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-016_en.pdf
https://jvn.jp/vu/JVNVU93383160/

Timeline