CVE-2023-5274
Last modified
CVE-2023-5274 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. Improper Input Validation vulnerability in simulation function of GX Works2 allows an attacker to cause a denial-of-service (DoS) condition on the function by sending specially crafted packets. However, the attacker would need to send the packets from within the same personal computer where the function is running. . EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Improper Input Validation vulnerability in simulation function of GX Works2 allows an attacker to cause a denial-of-service (DoS) condition on the function by sending specially crafted packets. However, the attacker would need to send the packets from within the same personal computer where the function is running.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mitsubishielectric | Gx Works2 | All versions |
References
- https://jvn.jp/vu/JVNVU98760962/index.htmlThird Party Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-331-03Third Party Advisory, US Government Resource
- https://jvn.jp/vu/JVNVU98760962/index.htmlThird Party Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-331-03Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-5274?
How severe is CVE-2023-5274?
How do I fix CVE-2023-5274?
Are you affected by CVE-2023-5274?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
