The vulnerabilities are cleartext storage of sensitive information, use of hard-coded password, insufficiently protected credentials, use of hard-coded cryptographic key, and cleartext storage of sensitive information in memory.
Successful exploitation of these remotely exploitable vulnerabilities could allow unauthorized users to gain access to the MELSEC iQ-R/F/L series CPU modules and the MELSEC iQ-R series OPC UA server module or to view and execute programs.
The following versions of Mitsubishi Electric FA Engineering Software suffer from the vulnerabilities:
- GX Works3:
— 1.000A or later and 1.011M and prior (affected by CVE-2022-25164, CVE-2022-29825, CVE-2022-29826, CVE-2022-29827, CVE-2022-29828, CVE-2022-29829, CVE-2022-29830)
— 1.015R or later and 1.086Q and prior (affected by CVE-2022-25164, CVE-2022-29825, CVE-2022-29826, CVE-2022-29827, CVE-2022-29828, CVE-2022-29829, CVE-2022-29830, CVE-2022-29831, CVE-2022-29832, CVE-2022-29833)
— 1.087R or later (affected by CVE-2022-25164, CVE-2022-29825, CVE-2022-29827, CVE-2022-29828, CVE-2022-29829, CVE-2022-29830, CVE-2022-29831, CVE-2022-29832, CVE-2022-29833) - MX OPC UA Module Configurator-R: All versions (affected by CVE-2022-25164)
In one issue, if this cleartext storage of sensitive information vulnerability is exploited, sensitive information could end up be disclosed. As a result, unauthorized users can gain access to the CPU module and the OPC UA server module.
CVE-2022-25164 is the case number for this vulnerability, which has a CVSS v3 base score of 8.6.
In addition, if this cleartext storage of sensitive information vulnerability is exploited, sensitive information could be disclosed. As a result, unauthorized users could view or execute programs.
CVE-2022-29826 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.8.
Also, if this use of hard-coded password vulnerability is exploited, sensitive information could be disclosed. As a result, unauthorized users could view or execute programs.
CVE-2022-29825 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 5.6.
In another issue, if this use of hard-coded password vulnerability is exploited, unauthorized users could obtain information about the safety CPU module project file.
CVE-2022-29831 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.5.
In addition, if this insufficiently protected credentials vulnerability is exploited, sensitive information could be disclosed. As a result, unauthorized users could access the safety CPU module.
CVE-2022-29833 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.8.
Also, If this use of hard-coded cryptographic key vulnerability is exploited, sensitive information could be disclosed. As a result, unauthorized users could view or execute programs.
CVE-2022-29827 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.8.
In addition, if this use of hard-coded cryptographic key vulnerability is exploited, sensitive information could be disclosed. As a result, unauthorized users could view or execute programs.
CVE-2022-29828 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.8.
In another issue, if this use of hard-coded cryptographic key vulnerability is exploited, sensitive information could be disclosed. As a result, unauthorized users could view or execute programs.
CVE-2022-29829 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.8.
In addition, ff this if this use of hard-coded cryptographic key vulnerability is exploited, sensitive information could be tampered with or disclosed. As a result, information about project files could be obtained without permission by unauthorized users.
CVE-2022-29830 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 9.1.
Also, if this cleartext storage of sensitive information in memory vulnerability is exploited, sensitive information could be disclosed. As a result, unauthorized users could obtain information about the safety CPU module project file.
CVE-2022-29832 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 3.7.
Anton Dorfman, Vladimir Nazarov, Dmitry Sklyarov, and Iliya Rogachev of Positive Technologies reported CVE-2022-25164, CVE-2022-29825, CVE-2022-29826, CVE-2022-29827, CVE-2022-29828, CVE-2022-29829, and CVE-2022-29830 to Mistubishi Electric. Ivan Speziale of Nozomi Networks reported CVE-2022-29831, CVE-2022-29832, and CVE-2022-29833 to CISA.
The product sees use mainly in the critical manufacturing sector, and on a global basis.
No known public exploits specifically target these vulnerabilities. However, an attacker with low skill level could leverage these low complexity vulnerabilities.
Mitsubishi Electric released and recommends users update to the latest version:
GX Works3 – CVE-2022-29826: Download fixed Ver. 1.090U or later
For all other listed vulnerabilities, Mitsubishi Electric released mitigations/workarounds for users to follow:
- Ensure malicious actors cannot access project files, configuration files, or security keys stored on the host machine via untrusted networks or hosts
- Install antivirus software on the host machine running the software
- Encrypt project files and security keys when sending or receiving over the Internet
- Use the “authentication with a certificate” function instead of “username / password authentication” for user authentication for access from OPC UA clients to MELSEC iQ-R series OPC UA server modules (MX OPC UA Module Configurator-R only)

