Home

Description

Cleartext Storage of Sensitive Information Vulnerability in GX Works2 all versions allows an attacker to disclose credential information stored in plaintext from project files. As a result, the attacker may be able to open project files protected by user authentication using disclosed credential information, and obtain or modify project information.

PUBLISHED Reserved 2025-04-18 | Published 2025-11-27 | Updated 2025-11-28 | Assigner Mitsubishi




MEDIUM: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-312 Cleartext Storage of Sensitive Information

Product status

Default status
unaffected

All versions
affected

Credits

Jiho Shin (M.S. graduate, Sungkyunkwan University) finder

References

www.mitsubishielectric.com/...nerability/pdf/2025-016_en.pdf vendor-advisory

jvn.jp/vu/JVNVU95288056/ government-resource

cve.org (CVE-2025-3784)

nvd.nist.gov (CVE-2025-3784)

Download JSON