Vulnerability record · CVE-2022-29830 · published 25 November 2022
CVE-2022-29830: Mitsubishielectric gx works3 hard-coded credentials vulnerability
Mitsubishielectric · Gx Works3
Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z, and Motion Control Setting(GX Works3 related software) versions from 1.000A to 1.065T allows a remote unauthenticated attacker to disclose or tamper with sensitive information. As a result, unauthenticated attackers may obtain information about project files illegally.
Description
Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z, and Motion Control Setting(GX Works3 related software) versions from 1.000A to 1.065T allows a remote unauthenticated attacker to disclose or tamper with sensitive information. As a result, unauthenticated attackers may obtain information about project files illegally.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://jvn.jp/vu/JVNVU97244961/index.html | Third Party AdvisoryVDB Entry |
| https://www.cisa.gov/uscert/ics/advisories/icsa-22-333-05 | |
| https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-015_en.pdf | MitigationVendor Advisory |
| https://jvn.jp/vu/JVNVU97244961/index.html | Third Party AdvisoryVDB Entry |
| https://www.cisa.gov/uscert/ics/advisories/icsa-22-333-05 | |
| https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-015_en.pdf | MitigationVendor Advisory |
Track CVE-2022-29830 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-29830), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.