CVE-2025-3784
BaseFortify
Publication date: 2025-11-27
Last updated on: 2025-12-08
Assigner: Mitsubishi Electric Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mitsubishi | electric | gx_works2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-312 | The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves the cleartext storage of sensitive information in GX Works2 project files. An attacker can access credential information stored in plaintext, which allows them to open project files that are supposed to be protected by user authentication. This means the attacker can obtain or modify project information without proper authorization.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized disclosure of credential information, enabling attackers to access and potentially modify protected project files. This compromises the confidentiality and integrity of project data, which could disrupt operations or lead to misuse of sensitive project information.